Description
A Use of Uninitialized Variable vulnerability affecting the EPRT file reading procedure in SOLIDWORKS eDrawings from Release SOLIDWORKS Desktop 2025 through Release SOLIDWORKS Desktop 2026 could allow an attacker to execute arbitrary code while opening a specially crafted EPRT file.
Published: 2026-02-16
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

A vulnerability in the EPRT file reading procedure of SOLIDWORKS eDrawings can allow an attacker to execute arbitrary code when opening a specially crafted EPRT file. The flaw is a use of an uninitialized variable, which leads to undefined behavior and can be exploited to run arbitrary instructions under the context of the current user. This type of flaw poses a significant risk to confidentiality, integrity, and availability of the affected system.

Affected Systems

The affected product is Dassault Systèmes SOLIDWORKS eDrawings in the 2025 and 2026 release lines, including all specified service packs: 2025 through 2025 sp5.0, 2025 sp4.0, 2025 sp3.0, 2025 sp2.0, 2025 sp1.0, and 2026 sp1.1.

Risk and Exploitability

The CVSS score for this issue is 7.8, indicating a high severity. The EPSS score is below 1%, suggesting a low probability of exploitation as of the latest data. This vulnerability is not listed in the CISA KEV catalog. The attack vector is most likely local, relying on the user opening a malicious EPRT file. Because the flaw arises from improper variable initialization during file parsing, an attacker can control the payload by crafting the file, but requires that the target user has privileges sufficient to run the application and that the file is opened in an unsecured context.

Generated by OpenCVE AI on April 17, 2026 at 19:04 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update SOLIDWORKS eDrawings to the latest patched release that removes the uninitialized variable flaw.
  • If a patch is unavailable, configure the application or system to block or quarantine EPRT file handling from untrusted sources and restrict access to the file type.
  • Deploy monitoring for anomalous process creation or file access patterns related to eDrawings, and alert on execution of EPRT files from unexpected locations.

Generated by OpenCVE AI on April 17, 2026 at 19:04 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 26 Feb 2026 18:30:00 +0000

Type Values Removed Values Added
First Time appeared 3ds
3ds solidworks Edrawings
CPEs cpe:2.3:a:3ds:solidworks_edrawings:2025:-:*:*:*:*:*:*
cpe:2.3:a:3ds:solidworks_edrawings:2025:sp1.0:*:*:*:*:*:*
cpe:2.3:a:3ds:solidworks_edrawings:2025:sp2.0:*:*:*:*:*:*
cpe:2.3:a:3ds:solidworks_edrawings:2025:sp3.0:*:*:*:*:*:*
cpe:2.3:a:3ds:solidworks_edrawings:2025:sp4.0:*:*:*:*:*:*
cpe:2.3:a:3ds:solidworks_edrawings:2025:sp5.0:*:*:*:*:*:*
cpe:2.3:a:3ds:solidworks_edrawings:2026:-:*:*:*:*:*:*
cpe:2.3:a:3ds:solidworks_edrawings:2026:sp1.1:*:*:*:*:*:*
Vendors & Products 3ds
3ds solidworks Edrawings

Tue, 17 Feb 2026 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 17 Feb 2026 09:00:00 +0000

Type Values Removed Values Added
First Time appeared Dassault Systemes
Dassault Systemes solidworks Edrawings
Vendors & Products Dassault Systemes
Dassault Systemes solidworks Edrawings

Mon, 16 Feb 2026 14:00:00 +0000

Type Values Removed Values Added
Description A Use of Uninitialized Variable vulnerability affecting the EPRT file reading procedure in SOLIDWORKS eDrawings from Release SOLIDWORKS Desktop 2025 through Release SOLIDWORKS Desktop 2026 could allow an attacker to execute arbitrary code while opening a specially crafted EPRT file.
Title Use of Uninitialized Variable vulnerability affecting the EPRT file reading procedure in SOLIDWORKS eDrawings from Release SOLIDWORKS Desktop 2025 through Release SOLIDWORKS Desktop 2026
Weaknesses CWE-457
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

3ds Solidworks Edrawings
Dassault Systemes Solidworks Edrawings
cve-icon MITRE

Status: PUBLISHED

Assigner: 3DS

Published:

Updated: 2026-02-26T14:44:20.234Z

Reserved: 2026-01-22T08:10:51.866Z

Link: CVE-2026-1333

cve-icon Vulnrichment

Updated: 2026-02-17T14:56:57.612Z

cve-icon NVD

Status : Analyzed

Published: 2026-02-16T14:16:18.003

Modified: 2026-02-26T18:15:50.280

Link: CVE-2026-1333

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-17T19:15:26Z

Weaknesses