Impact
An out‑of‑bounds read occurs while the eDrawings application parses EPRT configuration files. The flaw is triggered by a specially crafted file and can be used to execute arbitrary code in the context of the user who opens the file. The vulnerability is a direct memory corruption attack (CWE‑125) that compromises confidentiality, integrity, and availability of the affected system.
Affected Systems
Dassault Systèmes software users running SOLIDWORKS eDrawings from Release 2025 through Release 2026, including all service releases listed in the CVE data (sp1.0 to sp5.0 for 2025 and sp1.1 for 2026).
Risk and Exploitability
The CVSS score of 7.8 classifies the flaw as high severity. The EPSS score of less than 1 % indicates a low probability of widespread exploitation, and the vulnerability is not currently in the CISA KEV catalogue. Based on the described behavior, the likely attack vector is local, occurring when a user opens a malicious file, although an attacker could potentially deliver the file remotely if they gain file‑type access on a shared system.
OpenCVE Enrichment