CVE-2024-1847: Multiple vulnerabilities exist in file reading procedure in eDrawings from Release SOLIDWORKS 2023 through Release SOLIDWORKS 2024
Heap-based Buffer Overflow, Memory Corruption, Out-Of-Bounds Read, Out-Of-Bounds Write, Stack-based Buffer Overflow, Type Confusion, Uninitialized Variable, Use-After-Free vulnerabilities exist in the file reading procedure in eDrawings from Release SOLIDWORKS 2023 through Release SOLIDWORKS 2024. These vulnerabilities could allow an attacker to execute arbitrary code while opening a specially crafted CATPART, IPT, JT, SAT, STL, STP, XB or XT file. NOTE: CVE-2024-3298 and CVE-2024-3299 were SPLIT from this ID.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-1847?
CVE-2024-1847 is classified as a high-severity vulnerability due to its potential for memory corruption and exploitation.
How do I fix CVE-2024-1847?
To fix CVE-2024-1847, users should update eDrawings to the latest version provided by Dassault Systèmes.
What types of vulnerabilities are associated with CVE-2024-1847?
CVE-2024-1847 includes heap-based buffer overflow, memory corruption, out-of-bounds read/write, stack-based buffer overflow, type confusion, uninitialized variable, and use-after-free vulnerabilities.
Which versions of eDrawings are affected by CVE-2024-1847?
CVE-2024-1847 affects eDrawings from Release SOLIDWORKS 2023 through Release 2024.
What impact does CVE-2024-1847 have on users?
CVE-2024-1847 can lead to system crashes and potential remote code execution, compromising user data and system integrity.