The HCL DFMPro, DFXAnalytics and DFXServer installers are affected by ‘Insecure file permissions Leading to Privilege Escalation’ vulnerability, which enables any logged-in non-administrative user to overwrite or replace the executable file with a malicious binary.
Metrics
Affected Vendors & Products
References
History
Fri, 31 Jul 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Insecure File Permissions in HCL Software Installers Enable Privilege Escalation |
Wed, 29 Jul 2026 02:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Privilege Escalation via Insecure File Permissions in HCL DFMPro, DFXAnalytics, and DFXServer Installers |
Tue, 28 Jul 2026 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Hcltech
Hcltech dfmpro For Catia Hcltech dfxanalytics Hcltech dfxserver |
|
| Vendors & Products |
Hcltech
Hcltech dfmpro For Catia Hcltech dfxanalytics Hcltech dfxserver |
Fri, 24 Jul 2026 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Privilege Escalation via Insecure File Permissions in HCL DFMPro, DFXAnalytics, and DFXServer Installers |
Fri, 17 Jul 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 17 Jul 2026 17:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The HCL DFMPro, DFXAnalytics and DFXServer installers are affected by ‘Insecure file permissions Leading to Privilege Escalation’ vulnerability, which enables any logged-in non-administrative user to overwrite or replace the executable file with a malicious binary. | |
| Weaknesses | CWE-732 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: HCL
Published: 2026-07-17T17:22:03.343Z
Updated: 2026-07-17T17:52:43.779Z
Reserved: 2025-09-22T15:00:11.102Z
Link: CVE-2025-59866
Updated: 2026-07-17T17:52:40.393Z
No data.
No data.