ZDI-25-285: Dassault Systèmes eDrawings Viewer SLDPRT File Parsing Use-After-Free Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Dassault Syst��mes eDrawings Viewer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2025-1884.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-25-285?
ZDI-25-285 is considered a critical vulnerability due to its potential for remote code execution.
What products are affected by ZDI-25-285?
ZDI-25-285 specifically affects Dassault Systèmes eDrawings Viewer.
How do I fix ZDI-25-285?
To mitigate ZDI-25-285, users should update to the latest version of Dassault Systèmes eDrawings Viewer as soon as it is available.
Can ZDI-25-285 be exploited without user interaction?
Exploitation of ZDI-25-285 requires user interaction, such as visiting a malicious page or opening a malicious file.
What type of attack does ZDI-25-285 enable?
ZDI-25-285 enables remote attackers to execute arbitrary code on affected installations of the software.