CVE-2025-7042
Last modified
CVE-2025-7042 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. Use After Free vulnerability exists in the IPT file reading procedure in SOLIDWORKS eDrawings on Release SOLIDWORKS Desktop 2025. This vulnerability could allow an attacker to execute arbitrary code while opening a specially crafted IPT file.. EPSS estimates a 0.16% chance of exploitation in the next 30 days.
Description
Use After Free vulnerability exists in the IPT file reading procedure in SOLIDWORKS eDrawings on Release SOLIDWORKS Desktop 2025. This vulnerability could allow an attacker to execute arbitrary code while opening a specially crafted IPT file.
Metrics
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2025-7042?
How severe is CVE-2025-7042?
How do I fix CVE-2025-7042?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-70368Worklenz version 2.1.5 contains a Stored Cross-Site Scriptin…5.4
- CVE-2025-7037SQL injection in Ivanti Endpoint Manager before version 2024…7.2
- CVE-2025-7038The LatePoint plugin for WordPress is vulnerable to Authenti…8.2
- CVE-2025-7039A flaw was found in glib. An integer overflow during tempora…3.7
- CVE-2025-70397jizhicms 2.5.6 is vulnerable to SQL Injection in Article/del…7.2
- CVE-2025-7040The Cloud SAML SSO plugin for WordPress is vulnerable to una…8.2
- CVE-2025-70420Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: non…
- CVE-2025-7044An Improper Input Validation vulnerability exists in the use…6.5
- CVE-2025-7045The Cloud SAML SSO plugin for WordPress is vulnerable to Ide…6.5
- CVE-2025-70457A Remote Code Execution (RCE) vulnerability exists in Source…9.8
- CVE-2025-70458A DOM-based Cross-Site Scripting (XSS) vulnerability exists …5.4
- CVE-2025-7046The Portfolio for Elementor & Image Gallery | PowerFolio plu…5.4
Are you affected by CVE-2025-7042?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
