ZDI-26-317: Siemens Simcenter Femap IPT File Parsing Memory Corruption Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Siemens Simcenter Femap. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2025-12659.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-26-317?
ZDI-26-317 is considered a critical vulnerability due to its potential for remote code execution.
How do I fix ZDI-26-317?
To remediate ZDI-26-317, update Siemens Simcenter Femap to the latest version available from Siemens.
What type of vulnerability is ZDI-26-317?
ZDI-26-317 is a memory corruption vulnerability that can be exploited for remote code execution.
Is user interaction required to exploit ZDI-26-317?
Yes, user interaction is required to exploit ZDI-26-317 as the target must open a malicious IPT file.
What are the consequences of ZDI-26-317 exploitation?
Exploitation of ZDI-26-317 could allow attackers to execute arbitrary code on the affected system.