CVE-2026-1284
7.8Dassault Systèmes · SOLIDWORKS eDrawings
A critical out of bounds write vulnerability in the SOLIDWORKS eDrawings EPRT file reader allows attackers to execute arbitrary code via a specially crafted file.
Executive summary
A critical out of bounds write flaw in Dassault Systèmes SOLIDWORKS eDrawings exposes users to remote code execution risks when opening malicious EPRT files.
Vulnerability
This is an out of bounds write vulnerability (CWE-787) triggered during the processing of EPRT files. The vulnerability allows an unauthenticated attacker to achieve arbitrary code execution on the host system if a user is enticed to open a specially crafted file.
Business impact
The potential for arbitrary code execution poses a severe risk to organizational security, as it could lead to full system compromise, data exfiltration, or the deployment of ransomware. Given the CVSS score of 7.8, the impact is considered High: it necessitates immediate attention, particularly in engineering environments where CAD file exchange is frequent and often perceived as trusted.
Remediation
Immediate Action: Review the official Dassault Systèmes security advisory at https://www.3ds.com/trust-center/security/security-advisories/cve-2026-1284 and apply all available security updates for affected SOLIDWORKS Desktop versions.
Proactive Monitoring: Monitor file integrity and endpoint logs for suspicious process execution patterns originating from the SOLIDWORKS eDrawings application.
Compensating Controls: Restrict the opening of EPRT files from untrusted or external sources and ensure that users operate with the principle of least privilege to limit the potential reach of a successful exploit.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Users of SOLIDWORKS eDrawings should treat this vulnerability with high urgency. Because the attack vector relies on the user opening a file, internal security awareness training should be supplemented with the immediate application of vendor patches. Failure to remediate could allow attackers to gain unauthorized control over engineering workstations.