CVE-2025-0831

7.8

Dassault Systèmes · SOLIDWORKS eDrawings

An out-of-bounds read vulnerability in the JT file parsing procedure of SOLIDWORKS eDrawings allows for potential arbitrary code execution when processing a malicious file.

Executive summary

A critical out-of-bounds read vulnerability in SOLIDWORKS eDrawings could allow an unauthenticated attacker to execute arbitrary code by convincing a user to open a specially crafted JT file.

Vulnerability

This is an out-of-bounds read vulnerability (CWE-125) occurring during the parsing of JT files. An attacker can trigger this flaw by providing a specially crafted file to an unsuspecting user, potentially leading to arbitrary code execution within the context of the application.

Business impact

The vulnerability carries a CVSS score of 7.8, reflecting its high potential for impact on confidentiality, integrity, and availability. Successful exploitation enables an attacker to execute code with the privileges of the logged-in user, which could result in complete system compromise, unauthorized data exfiltration, or the installation of persistent threats within the engineering environment.

Remediation

Immediate Action: Users must update to the latest patched version of SOLIDWORKS eDrawings as provided by Dassault Systèmes in their official security advisory.

Proactive Monitoring: Security teams should monitor endpoint logs for unexpected process execution or abnormal behavior originating from the eDrawings application when handling external JT files.

Compensating Controls: Implement strict file-handling policies that restrict the opening of untrusted or externally sourced JT files until the software has been updated.

Exploitation status

Public Exploit Available: exploit_available (unknown)

Analyst recommendation

Given the potential for arbitrary code execution, this vulnerability poses a significant risk to design and engineering workstations. Organizations should prioritize the deployment of vendor-supplied patches to all affected SOLIDWORKS Desktop 2025 installations immediately to eliminate the underlying memory corruption risk.

More Dassault Systèmes CVEs

Sources