ZDI-26-114: Dassault Systèmes eDrawings Viewer EPRT File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Dassault Syst��mes eDrawings Viewer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-1335.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-26-114?
The severity of ZDI-26-114 is classified as high due to its potential for remote code execution.
How do I fix ZDI-26-114?
To fix ZDI-26-114, users should update Dassault Systèmes eDrawings Viewer to the latest version that addresses the vulnerability.
What are the consequences of exploiting ZDI-26-114?
Exploiting ZDI-26-114 can allow remote attackers to execute arbitrary code on affected systems, leading to full system compromise.
Is user interaction required to exploit ZDI-26-114?
Yes, user interaction is required to exploit ZDI-26-114 as it involves opening a malicious EPRT file.
Which software is affected by ZDI-26-114?
The software affected by ZDI-26-114 is Dassault Systèmes eDrawings Viewer.