ZDI-CAN-28186: ZDI-26-096: Dassault Systèmes eDrawings Viewer EPRT File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability
Published Feb 13, 2026
·Updated
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Dassault Syst��mes eDrawings Viewer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-1283.
Affected Software
1 affected component
Dassault Systèmes eDrawings Viewer
Event History
Feb 13, 2026
Advisory Published
via ZDI·06:00 AM
Data Sourced
via ZDI·06:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-CAN-28186?
ZDI-CAN-28186 is classified as a critical vulnerability due to its potential for remote code execution.
2
How do I fix ZDI-CAN-28186?
To mitigate ZDI-CAN-28186, update the Dassault Systèmes eDrawings Viewer to the latest version available.
3
What type of vulnerability is ZDI-CAN-28186?
ZDI-CAN-28186 is a heap-based buffer overflow vulnerability.
4
What is required for an attacker to exploit ZDI-CAN-28186?
Exploitation of ZDI-CAN-28186 requires user interaction.
5
Which software is affected by ZDI-CAN-28186?
ZDI-CAN-28186 affects Dassault Systèmes eDrawings Viewer.