External risk intelligence

3DEXPERIENCE Station Launcher OS Command Injection.

CVE advisorySeverity: CRITICAL (CVSS 9.0)

CVE-2025-9976

The vulnerability affects the Station Launcher App, which is a client-side component installed on a user's machine to facilitate launching applications. While it involves network communication, it is not a public-facing service, edge gateway, or web application, making direct internet exposure uncommon.

OS Command Injection

Halo Surface Signal: 2 out of 5 — less likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A vulnerability in the Station Launcher App for the 3DEXPERIENCE platform could allow unauthorized code execution on user machines. This means a sophisticated attacker could potentially compromise individual workstations. The primary concern is confirming if this specific application is in use and if it presents any exposure.

  • Command execution flaw found in 3DEXPERIENCE.
  • Confirms if this specific application is in use.
  • Focus on confirming relevance and potential exposure.

Attack Path

How an attacker could exploit the issue

An attacker could exploit this vulnerability by tricking a user into launching the Station Launcher App, potentially through a malicious link or file. Once the app is running, the attacker could send specially crafted commands that the app would execute with elevated privileges on the user's computer. This could lead to the attacker gaining control over the infected machine, allowing them to run their own code and access sensitive data.

  • Requires user interaction to launch the app.
  • Triggered by sending malicious commands.
  • Risk of arbitrary code execution.

Live Threat

Current exploitation, exposure, and threat context

A vulnerability in the Station Launcher App could allow an attacker to execute arbitrary code on a user's machine under specific conditions. This occurs when a user interacts with a malicious link or file, potentially leading to unauthorized code execution.

  • User's machine and installed software.
  • Malicious link or file interaction.
  • Arbitrary code execution on the machine.

Operational Fix

Recommended remediation, mitigation, and detection steps

This critical OS command injection vulnerability in the Station Launcher App impacts users running specific releases of the 3DEXPERIENCE platform. The first practical step is for application owners and infrastructure teams to identify all instances of the affected software, determine their network reachability and business criticality, and then assign ownership for remediation planning.

  • Application and Infrastructure teams own the issue.
  • Verify Station Launcher App reachability and criticality.
  • Plan remediation based on assessed risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the 3DEXPERIENCE Station Launcher App?

The Station Launcher is a client-side component within the 3DEXPERIENCE platform used to manage and start various engineering and design applications. It acts as a bridge between the platform's cloud or server environments and the local machine, ensuring that necessary software tools are properly initialized for users working on complex projects.

What does OS Command Injection mean for CVE-2025-9976?

This vulnerability, classified as CWE-78, occurs when an application improperly filters input before passing it to the operating system. In the context of CVE-2025-9976, it means an attacker could insert unauthorized system commands into the application, which the computer would then execute as if they were legitimate instructions.

How is this vulnerability triggered?

An attacker must trick a user into interacting with a malicious link or file that initiates the Station Launcher App. The flaw is not triggered by simply having the software installed or connected to a network; it requires that specific user action to process the crafted commands within the application environment.

Is my system at risk if it runs the Station Launcher?

According to Halo Surface Signal, this component is typically a client-side tool rather than a public-facing service or web application. Because it is not designed to be reachable directly from the internet, the likelihood of an external, automated attack is generally considered low, though local user interaction remains a vector.

What should I do if I use the 3DEXPERIENCE platform?

You should first verify if your workstations have the Station Launcher installed and identify which releases are in use, specifically checking against the R2022x through R2025x range. Once identified, consult your infrastructure team to assess the software's network role and business criticality to prioritize your security planning.

References