CVE-2026-34223
largeClient Code Execution via malicious graphics documents in Siemens Desigo CC
Siemens Desigo CC client applications (ClickOnce, Flex, and Installed Client variants) insufficiently validate scripts embedded in user-defined graphics documents, enabling script injection (CWE-94). To trigger it, an attacker must craft a graphics document containing malicious script commands and entice a user with sufficient privileges to open it in the client application; the embedded script then executes within that client instance. Successful exploitation allows the attacker to write arbitrary files to the client's operating system, which can lead to full compromise of the client workstation and lateral movement within the organization's network. All client variants and versions listed (V6 through V9) are affected, so operators and engineers running Desigo CC building-management clients are in scope. Exploitation has not been observed: there is no public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS assigns a roughly 0.1% probability of exploitation within 30 days (3rd percentile).
What to do: No fixed versions are listed in this record, so check the Siemens ProductCERT advisory for CVE-2026-34223 and apply updated client builds when released. Until then, only open or import user-defined graphics documents from trusted sources, avoid shared graphics libraries of unknown origin, and run Desigo CC clients under least-privilege accounts to limit file-write impact. Inventory which client variants (ClickOnce, Flex, Installed) and versions (V6–V9) are deployed and whether users routinely open externally supplied graphics.
| Siemens Desigo CC ClickOnce Client | V6 (all versions) |
| Siemens Desigo CC ClickOnce Client | V7 (all versions) |
| Siemens Desigo CC family | V8 (all versions) |
| Siemens Desigo CC family | V9 (all versions) |
| Siemens Desigo CC Flex Client | V6 (all versions) |
| Siemens Desigo CC Flex Client | V7 (all versions) |
| Siemens Desigo CC Installed Client | V6 (all versions) |
| Siemens Desigo CC Installed Client | V7 (all versions) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A vulnerability has been identified in Desigo CC ClickOnce Client V6 (All versions), Desigo CC ClickOnce Client V7 (All versions), Desigo CC family V8 (All versions), Desigo CC family V9 (All versions), Desigo CC Flex Client V6 (All versions), Desigo CC Flex Client V7 (All versions), Desigo CC Installed Client V6 (All versions), Desigo CC Installed Client V7 (All versions). The affected application is vulnerable to Client Code Execution (CCE) due to insufficient input validation when handling scripts embedded within user-defined graphics documents. Specifically, when the script within a graphics document is designed or modified by an attacker to include malicious commands. When a user opens a compromised graphics document, the embedded script is executed on the client application instance, allowing an attacker to write arbitrary files to the client's operating system. Successful exploitation requires an attacker to craft a malicious graphics document and entice a user with sufficient privileges to display it. This could lead to compromise of the client operating system and potential lateral movement within the organization.
- Weakness
- CWE-94
- Vector
- CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.