CVE-2024-3299: Out-Of-Bounds Write, Use of Uninitialized Resource and Use-After-Free vulnerabilities exist in the SLDDRW and SLDPRT file reading procedure in eDrawings from Release SOLIDWORKS 2023 through Release SOLIDWORKS 2024
Out-Of-Bounds Write, Use of Uninitialized Resource and Use-After-Free vulnerabilities exist in the file reading procedure in eDrawings from Release SOLIDWORKS 2023 through Release SOLIDWORKS 2024. These vulnerabilities could allow an attacker to execute arbitrary code while opening a specially crafted SLDDRW or SLDPRT file. NOTE: this vulnerability was SPLIT from CVE-2024-1847.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-3299?
CVE-2024-3299 has a high severity rating due to its potential to allow arbitrary code execution.
How do I fix CVE-2024-3299?
To fix CVE-2024-3299, update eDrawings to the latest version provided by SOLIDWORKS that addresses these vulnerabilities.
Which versions are affected by CVE-2024-3299?
CVE-2024-3299 affects eDrawings from SOLIDWORKS 2023 through SOLIDWORKS 2024.
What types of vulnerabilities are associated with CVE-2024-3299?
CVE-2024-3299 involves Out-Of-Bounds Write, Use of Uninitialized Resource, and Use-After-Free vulnerabilities.
Can CVE-2024-3299 be exploited remotely?
Yes, CVE-2024-3299 can potentially be exploited remotely if an attacker can trick a user into opening a malicious file.