ZDI-CAN-26029: ZDI-25-285: Dassault Systèmes eDrawings Viewer SLDPRT File Parsing Use-After-Free Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Dassault Syst��mes eDrawings Viewer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2025-1884.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-26029?
The severity of ZDI-CAN-26029 is high as it allows remote attackers to execute arbitrary code.
How do I fix ZDI-CAN-26029?
To fix ZDI-CAN-26029, ensure that you update the Dassault Systèmes eDrawings Viewer to the latest version.
Who is affected by ZDI-CAN-26029?
Users of Dassault Systèmes eDrawings Viewer are affected by ZDI-CAN-26029.
Is user interaction required to exploit ZDI-CAN-26029?
Yes, user interaction is required as the target must visit a malicious page or open a malicious file.
What can attackers do with ZDI-CAN-26029?
Attackers can execute arbitrary code on affected installations of Dassault Systèmes eDrawings Viewer.