CVE-2025-59866

Summary

The HCL DFMPro, DFXAnalytics and DFXServer installers are affected by ‘Insecure file permissions Leading to Privilege Escalation’ vulnerability, which enables any logged-in non-administrative user to overwrite or replace the executable file with a malicious binary.

Affected Software

VendorProductVersion RangeStatus
HCLSoftwareDFMPro for CATIAv4.1affected
HCLSoftwareDFXAnalyticsv3.1affected
HCLSoftwareDFXServerv3.1affected

Weaknesses

  • CWE-732: CWE-732: Incorrect Permission Assignment for Critical Resource

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References