ZDI-CAN-28404: ZDI-26-114: Dassault Systèmes eDrawings Viewer EPRT File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Dassault Syst��mes eDrawings Viewer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-1335.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-28404?
ZDI-CAN-28404 is classified as a critical remote code execution vulnerability.
How do I fix ZDI-CAN-28404?
To fix ZDI-CAN-28404, install the latest security updates provided by Dassault Systèmes for eDrawings Viewer.
What types of attacks can ZDI-CAN-28404 facilitate?
ZDI-CAN-28404 can facilitate arbitrary code execution attacks, allowing remote attackers to execute malicious code.
What versions of Dassault Systèmes eDrawings Viewer are affected by ZDI-CAN-28404?
ZDI-CAN-28404 affects all versions of Dassault Systèmes eDrawings Viewer prior to the security fix.
Does exploitation of ZDI-CAN-28404 require user interaction?
Yes, exploitation of ZDI-CAN-28404 requires user interaction for the remote code execution to occur.