This article goes over two vulnerabilities for eDrawings 2025 & 2026:
- CVE-2026-1283: A Heap-based Buffer Overflow vulnerability affecting the EPRT-file reading procedure. This vulnerability could allow an attacker to execute arbitrary code while opening a specially crafted EPRT file.
- CVE-2026-1284: An Out-Of-Bounds Write vulnerability affecting the EPRT-file reading procedure. This vulnerability could allow an attacker to execute arbitrary code while opening a specially crafted EPRT file.
Here are the affected versions:
- eDrawings Viewer 2025 SP0 - SP5
- eDrawings Commercial 2025 SP0 - 2026 SP0
At this time, there is no known impact for other products. The latest information on these vulnerabilities can be found through these SolidWorks QA articles & Dassault Systèmes website:
- https://support.3ds.com/knowledge-base/?q=docid:QA00000442322
- https://support.3ds.com/knowledge-base/?q=docid:QA00000442323
- https://www.3ds.com/trust-center/security/security-advisories
Solution
The fix for these vulnerabilities is included in eDrawings 2026 SP1.1 and newer. The latest version of eDrawings Viewer can be downloaded from: https://www.solidworks.com/support/free-downloads
For the Commercial version of eDrawings, which is installed with SOLIDWORKS, upgrade to 2026 SP1.1 or newer. The latest version of SOLIDWORKS can be downloaded here: https://www.solidworks.com/support/downloads
For additional support, existing customers can submit a ticket or new customers can contact Hawk Ridge Systems.
Comments
Article is closed for comments.