ZDI-CAN-26017: ZDI-25-286: Dassault Systèmes eDrawings Viewer OBJ File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Dassault Syst��mes eDrawings Viewer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2025-1883.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-26017?
The severity of ZDI-CAN-26017 is critical as it allows remote code execution on affected systems.
How do I fix ZDI-CAN-26017?
To remediate ZDI-CAN-26017, update Dassault Systèmes eDrawings Viewer to the latest version provided by the vendor.
What versions of Dassault Systèmes eDrawings Viewer are affected by ZDI-CAN-26017?
ZDI-CAN-26017 affects all versions of Dassault Systèmes eDrawings Viewer prior to the patched version.
Is user interaction required to exploit ZDI-CAN-26017?
Yes, user interaction is required as the target must visit a malicious page or open a malicious file to exploit ZDI-CAN-26017.
What could happen if ZDI-CAN-26017 is exploited?
If ZDI-CAN-26017 is exploited, attackers could execute arbitrary code remotely, leading to potential data compromise or system damage.