ZDI-26-095: Dassault Systèmes eDrawings Viewer EPRT File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Dassault Syst��mes eDrawings Viewer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-1284.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-26-095?
The severity of ZDI-26-095 is critical due to the potential for remote code execution.
How do I fix ZDI-26-095?
To fix ZDI-26-095, update to the latest version of Dassault Systèmes eDrawings Viewer as soon as possible.
What types of attacks can exploit ZDI-26-095?
ZDI-26-095 can be exploited by remote attackers to execute arbitrary code on vulnerable installations.
Is user interaction required to exploit ZDI-26-095?
Yes, user interaction is required to exploit the vulnerability ZDI-26-095.
What software is affected by ZDI-26-095?
The software affected by ZDI-26-095 is Dassault Systèmes eDrawings Viewer.