Description
An Out-Of-Bounds Write vulnerability affecting the EPRT file reading procedure in SOLIDWORKS eDrawings from Release SOLIDWORKS Desktop 2025 through Release SOLIDWORKS Desktop 2026 could allow an attacker to execute arbitrary code while opening a specially crafted EPRT file.
Published: 2026-01-26
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

An out‑of‑bounds write flaw exists in the EPRT file reading routine of SOLIDWORKS eDrawings. When an attacker opens a specially crafted EPRT file, the flaw allows the program to write beyond an intended buffer, potentially leading to arbitrary code execution. The weakness is classified as CWE‑787, a classic memory corruption vulnerability that can compromise confidentiality, integrity and availability by giving malicious code full control over the host system.

Affected Systems

Dassault Systèmes' SOLIDWORKS eDrawings is impacted, specifically Release SOLIDWORKS Desktop 2025 and all builds through Release SOLIDWORKS Desktop 2026. All deployments using these versions are considered vulnerable unless patched or updated to a later release that addresses the flaw.

Risk and Exploitability

The CVSS v3.1 score of 7.8 indicates a high severity level. EPSS is below 1%, suggesting that, as of the latest data, exploitation attempts are rare or unlikely, and the vulnerability is not currently listed in the CISA KEV catalog. Nonetheless, the flaw can be leveraged by tricking a user or by an attacker who can place a malicious EPRT file on a machine where the user runs eDrawings. Because the exploitation requires the file to be processed by the application, the likely attack vector is local or via social engineering; a remote exploitation scenario would require the attacker to deliver the file to or cause the user to open it. The combination of high severity and the potential for arbitrary code execution warrants immediate action.

Generated by OpenCVE AI on April 18, 2026 at 15:01 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update to a SOLIDWORKS Desktop version that includes the vendor’s fix (e.g., 2027 or later);
  • Until a patch is available, disable automatic opening of EPRT files or restrict them to trusted sources only;
  • Continuously monitor application logs for abnormal EPRT file processing or attempts to inject code, and isolate affected endpoints when suspicious activity is detected.

Generated by OpenCVE AI on April 18, 2026 at 15:01 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 03 Feb 2026 13:15:00 +0000

Type Values Removed Values Added
Description An Out-Of-Bounds Write vulnerability affecting the EPRT file reading procedure in SOLIDWORKS eDrawings from Release SOLIDWORKS 2025 through Release SOLIDWORKS 2026 could allow an attacker to execute arbitrary code while opening a specially crafted EPRT file. An Out-Of-Bounds Write vulnerability affecting the EPRT file reading procedure in SOLIDWORKS eDrawings from Release SOLIDWORKS Desktop 2025 through Release SOLIDWORKS Desktop 2026 could allow an attacker to execute arbitrary code while opening a specially crafted EPRT file.
Title Out-Of-Bounds Write vulnerability affecting the EPRT file reading procedure in SOLIDWORKS eDrawings from Release SOLIDWORKS 2025 through Release SOLIDWORKS 2026 Out-Of-Bounds Write vulnerability affecting the EPRT file reading procedure in SOLIDWORKS eDrawings from Release SOLIDWORKS Desktop 2025 through Release SOLIDWORKS Desktop 2026

Tue, 27 Jan 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Dassault
Dassault edrawings
Vendors & Products Dassault
Dassault edrawings

Mon, 26 Jan 2026 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 26 Jan 2026 13:45:00 +0000

Type Values Removed Values Added
Description An Out-Of-Bounds Write vulnerability affecting the EPRT file reading procedure in SOLIDWORKS eDrawings from Release SOLIDWORKS 2025 through Release SOLIDWORKS 2026 could allow an attacker to execute arbitrary code while opening a specially crafted EPRT file.
Title Out-Of-Bounds Write vulnerability affecting the EPRT file reading procedure in SOLIDWORKS eDrawings from Release SOLIDWORKS 2025 through Release SOLIDWORKS 2026
Weaknesses CWE-787
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

Dassault Edrawings
cve-icon MITRE

Status: PUBLISHED

Assigner: 3DS

Published:

Updated: 2026-02-26T15:04:51.839Z

Reserved: 2026-01-21T11:57:40.910Z

Link: CVE-2026-1284

cve-icon Vulnrichment

Updated: 2026-01-26T14:39:06.576Z

cve-icon NVD

Status : Deferred

Published: 2026-01-26T14:15:57.020

Modified: 2026-04-15T00:35:42.020

Link: CVE-2026-1284

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-18T15:15:03Z

Weaknesses