CVE-2025-23402
CVSS 3.1 Score 7.8 of 10 (high)
Details
Published Mar 11, 2025
CWE ID 416
Summary
CVE-2025-23402 is a use-after-free vulnerability affecting various versions of Teamcenter Visualization (V14.3, V2312, V2406, V2412), and Tecnomatix Plant Simulation (V2302, V2404). These applications contain a flaw that can be triggered while parsing maliciously crafted WRL files. Successful exploitation of this vulnerability allows an attacker to execute code in the context of the current process. Affected versions are all those prior to V14.3.0.13, V2312.0009, V2406.0007, V2412.0002, V2302.0021, and V2404.0010.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.