ZDI-25-286: Dassault Systèmes eDrawings Viewer OBJ File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Dassault Syst��mes eDrawings Viewer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2025-1883.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-25-286?
The vulnerability ZDI-25-286 is considered high severity due to its ability to allow remote code execution.
How do I fix ZDI-25-286?
To mitigate ZDI-25-286, users should update their Dassault Systèmes eDrawings Viewer to the latest patched version.
What are the risks associated with ZDI-25-286?
The risks of ZDI-25-286 include potential remote code execution by an attacker if the user interacts with malicious content.
Who is affected by ZDI-25-286?
ZDI-25-286 affects installations of Dassault Systèmes eDrawings Viewer on user devices.
Is user interaction required to exploit ZDI-25-286?
Yes, user interaction is required as the target must visit a malicious page or open a malicious file to exploit ZDI-25-286.