An Out-Of-Bounds Write vulnerability affecting the EPRT file reading procedure in SOLIDWORKS eDrawings from Release SOLIDWORKS Desktop 2025 through Re...
Description
An Out-Of-Bounds Write vulnerability affecting the EPRT file reading procedure in SOLIDWORKS eDrawings from Release SOLIDWORKS Desktop 2025 through Release SOLIDWORKS Desktop 2026 could allow an attacker to execute arbitrary code while opening a specially crafted EPRT file
AI Analyst Comment
Remediation
Apply vendor security updates immediately. Monitor for exploitation attempts and review access logs.
---METADATA---
VENDOR: SOLIDWORKS
PRODUCT: eDrawings
AFFECTED_VERSIONS: SOLIDWORKS Desktop 2025 through 2026
---END_METADATA---
Description Summary:
An Out-Of-Bounds Write vulnerability in the EPRT file reading procedure of SOLIDWORKS eDrawings allows for arbitrary code execution via crafted files.
Executive Summary:
SOLIDWORKS eDrawings is susceptible to an Out-Of-Bounds Write vulnerability that enables remote code execution, posing a high risk to workstations handling CAD data.
Vulnerability Details
CVE-ID: CVE-2026-1335
Affected Software: SOLIDWORKS eDrawings
Affected Versions: Release SOLIDWORKS Desktop 2025 through Release SOLIDWORKS Desktop 2026
Vulnerability: This vulnerability involves an Out-Of-Bounds Write during the processing of EPRT files. An unauthenticated attacker can leverage this flaw by providing a specially crafted file that, when opened, writes malicious data outside of intended memory boundaries.
Business Impact
Exploitation of this flaw can lead to complete loss of system integrity and the execution of unauthorized commands with user-level permissions. The high CVSS score of 7.8 is justified by the ease with which a malicious file can be distributed via phishing or social engineering to compromise high-value engineering targets.
Remediation Plan
Immediate Action: Deploy the official vendor security patches for SOLIDWORKS Desktop 2025 and 2026 immediately to remediate the vulnerable file-reading function.
Proactive Monitoring: Use endpoint security tools to alert on memory corruption events or unexpected network connections originating from the eDrawings application.
Compensating Controls: Utilize a Web Gateway or Email Security Appliance to scan and block EPRT files containing suspicious structures or those originating from unverified external sources.
Exploitation Status
Public Exploit Available: false
Analyst Notes: As of February 17, 2026, there is no public information indicating active exploitation of this vulnerability. The technical nature of an Out-Of-Bounds Write makes it a highly reliable vector for developing stable exploits.
Analyst Recommendation
Immediate remediation is required to protect against potential code execution attacks. Organizations must ensure that all instances of eDrawings are updated to the latest version. Delaying these updates leaves the environment vulnerable to targeted attacks aimed at compromising industrial designs.