eDrawings Vulnerability CVE-2026-1283 & CVE-2026-1284

This article goes over two vulnerabilities for eDrawings 2025 & 2026:

  1. CVE-2026-1283: A Heap-based Buffer Overflow vulnerability affecting the EPRT-file reading procedure. This vulnerability could allow an attacker to execute arbitrary code while opening a specially crafted EPRT file.
  2. CVE-2026-1284: An Out-Of-Bounds Write vulnerability affecting the EPRT-file reading procedure. This vulnerability could allow an attacker to execute arbitrary code while opening a specially crafted EPRT file.

Here are the affected versions:

  1. eDrawings Viewer 2025 SP0 - SP5
  2. eDrawings Commercial 2025 SP0 - 2026 SP0

At this time, there is no known impact for other products. The latest information on these vulnerabilities can be found through these SolidWorks QA articles & Dassault Systèmes website: 

  1. https://support.3ds.com/knowledge-base/?q=docid:QA00000442322
  2. https://support.3ds.com/knowledge-base/?q=docid:QA00000442323 
  3. https://www.3ds.com/trust-center/security/security-advisories 

Solution

The fix for these vulnerabilities is included in eDrawings 2026 SP1.1 and newer. The latest version of eDrawings Viewer can be downloaded from: https://www.solidworks.com/support/free-downloads

For the Commercial version of eDrawings, which is installed with SOLIDWORKS, upgrade to 2026 SP1.1 or newer. The latest version of SOLIDWORKS can be downloaded here: https://www.solidworks.com/support/downloads 

For additional support, existing customers can submit a ticket or new customers can contact Hawk Ridge Systems.

 

 

Was this article helpful?
0 out of 0 found this helpful

Articles in this section

Comments

0 comments

Article is closed for comments.