First published: Wed Jul 12 2023(Updated: )
Use-After-Free, Out-of-bounds Write and Heap-based Buffer Overflow vulnerabilities exist in the DWG and DXF file reading procedure in SOLIDWORKS Desktop from Release SOLIDWORKS 2021 through Release SOLIDWORKS 2023. These vulnerabilities could allow an attacker to execute arbitrary code while opening a specially crafted DWG or DXF file.
Credit: 3DS.Information-Security@3ds.com
Affected Software | Affected Version | How to fix |
---|---|---|
Solidworks Product Data Management | >=2021<=2023 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerabilities in SOLIDWORKS Desktop include Use-After-Free, Out-of-bounds Write, and Heap-based Buffer Overflow.
These vulnerabilities can be exploited by an attacker to execute arbitrary code while opening DWG and DXF files.
CVE-2023-2763 has a severity rating of high (7).
The Common Weakness Enumeration (CWE) numbers associated with these vulnerabilities are 119, 416, and 787.
You can find more information about these vulnerabilities on the 3DS website at [https://www.3ds.com/vulnerability/advisories](https://www.3ds.com/vulnerability/advisories).