CVE-2024-3298: Out-Of-Bounds Write and Type Confusion vulnerabilities exist in the DWG and DXF file reading procedure in eDrawings from Release SOLIDWORKS 2023 through Release SOLIDWORKS 2024
Out-Of-Bounds Write and Type Confusion vulnerabilities exist in the file reading procedure in eDrawings from Release SOLIDWORKS 2023 through Release SOLIDWORKS 2024. These vulnerabilities could allow an attacker to execute arbitrary code while opening a specially crafted DWG or DXF. NOTE: this vulnerability was SPLIT from CVE-2024-1847.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-3298?
CVE-2024-3298 is categorized as a high-severity vulnerability due to its potential to allow attackers to execute arbitrary code.
How do I fix CVE-2024-3298?
To fix CVE-2024-3298, ensure that you update to the latest version of SOLIDWORKS eDrawings that addresses this vulnerability.
Which software versions are affected by CVE-2024-3298?
CVE-2024-3298 affects SOLIDWORKS eDrawings from Release 2023 through Release 2024.
What types of attacks can occur due to CVE-2024-3298?
CVE-2024-3298 may allow attackers to execute arbitrary code by opening specially crafted DWG or DXF files.
Is there a workaround for CVE-2024-3298?
There are no documented workarounds for CVE-2024-3298; applying the latest updates is the recommended action.