First published: Thu Apr 04 2024(Updated: )
Out-Of-Bounds Write and Type Confusion vulnerabilities exist in the file reading procedure in eDrawings from Release SOLIDWORKS 2023 through Release SOLIDWORKS 2024. These vulnerabilities could allow an attacker to execute arbitrary code while opening a specially crafted DWG or DXF. NOTE: this vulnerability was SPLIT from CVE-2024-1847.
Credit: 3DS.Information-Security@3ds.com
Affected Software | Affected Version | How to fix |
---|---|---|
SOLIDWORKS eDrawings | >=2023<=2024 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-3298 is categorized as a high-severity vulnerability due to its potential to allow attackers to execute arbitrary code.
To fix CVE-2024-3298, ensure that you update to the latest version of SOLIDWORKS eDrawings that addresses this vulnerability.
CVE-2024-3298 affects SOLIDWORKS eDrawings from Release 2023 through Release 2024.
CVE-2024-3298 may allow attackers to execute arbitrary code by opening specially crafted DWG or DXF files.
There are no documented workarounds for CVE-2024-3298; applying the latest updates is the recommended action.