Executive brief
HCL DFMPro, DFXAnalytics, and DFXServer installers contain a security flaw where file permissions are not correctly restricted. This allows a standard user who is already logged into a computer to replace legitimate software files with malicious ones. If an administrator later runs these files, the attacker could gain higher-level system privileges, potentially compromising the security of the workstation.
Technical details
A privilege escalation vulnerability exists in the installers for HCL DFMPro, DFXAnalytics, and DFXServer due to incorrect permission assignment for critical resources (CWE-732). The installers set insecure file permissions on executable files, allowing a local, non-administrative user to overwrite or replace them with a malicious binary. Exploitation requires local access and typically some level of user interaction or a high-privilege process executing the tampered file. This could allow an attacker to execute arbitrary code with the privileges of the user or service running the modified executable.
Affected products
- HCL Software DFMPro for CATIA v4.1
- HCL Software DFXAnalytics v3.1
- HCL Software DFXServer v3.1
Timeline
- 2026-07-17: disclosed: Initial disclosure by HCL Software
- 2026-07-17: advisory: NVD record published