SOLIDWORKS eDrawings OOB Read Vulnerability (CVE-2026-1334)
CVE-2026-1334
High-severity OOB read in SOLIDWORKS eDrawings (Desktop 2025-2026) allows attackers to exploit EPRT files. Update to patched version promptly to mitigate data exposure.
Vendor-confirmed - CVE-2026-1334 is a high code execution vulnerability in SOLIDWORKS eDrawings Desktop 2025 through 2026 that lets an attacker execute arbitrary code by tricking a user into opening a malicious EPRT file. Update to the patched version immediately.
Overview
A significant security vulnerability has been identified in SOLIDWORKS eDrawings, a widely used application for viewing and sharing 3D models and 2D drawings. This flaw could allow an attacker to take control of an affected system.
Vulnerability Explained
In simple terms, the vulnerability exists in the part of the software that reads specific 3D model files (EPRT files). Due to a programming error, the software does not properly check the boundaries of the data it is reading from a malicious file. This “Out-of-Bounds Read” error can be exploited to trick the software into executing malicious code embedded within the file by the attacker.
Affected Software:
- SOLIDWORKS eDrawings from SOLIDWORKS Desktop 2025 through SOLIDWORKS Desktop 2026.
Potential Impact
The primary risk is that an attacker could create a specially crafted EPRT file designed to exploit this flaw. If a user opens this malicious file with a vulnerable version of eDrawings, the attacker could potentially execute arbitrary code on the victim’s computer. This could lead to:
- Full system compromise.
- Installation of malware, ransomware, or spyware.
- Theft of sensitive design data or intellectual property.
- Lateral movement within a corporate network.
The vulnerability is rated as HIGH severity with a CVSS score of 7.8, indicating a considerable threat, especially in engineering and design environments.
Remediation and Mitigation Steps
Immediate action is required to protect your systems.
- Apply Official Updates: Dassault Systèmes, the developer of SOLIDWORKS, has released security updates to address this vulnerability. You must update to a patched version of SOLIDWORKS eDrawings as soon as possible. Check with your SOLIDWORKS administrator or reseller for the specific update pertaining to your release.
- Exercise Caution with Files: Until updates are applied, users should be extremely cautious with EPRT files received from untrusted or unexpected sources. Do not open such files.
- Network and Email Filtering: If possible, use email gateways and network security tools to block or quarantine EPRT file attachments, especially from external senders, as an interim measure.
- Principle of Least Privilege: Ensure users do not operate with administrative privileges on their workstations. This can help limit the impact of potential code execution.
Reference: This vulnerability is tracked as CVE-2026-1334. Please refer to official communications from Dassault Systèmes for the most detailed and current patching information.
Never miss a critical vulnerability
Get real-time security alerts delivered to your preferred platform.
Related Advisories
A Use of Uninitialized Variable vulnerability affecting the EPRT file reading procedure in SOLIDWORKS eDrawings from Release SOLIDWORKS Desktop 2025 through Release SOLIDWORKS Desktop 2026 could allow...
An Out-Of-Bounds Write vulnerability affecting the EPRT file reading procedure in SOLIDWORKS eDrawings from Release SOLIDWORKS Desktop 2025 through Release SOLIDWORKS Desktop 2026 could allow an attac...
Out of bounds read and write in V8 in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Hi...
Out-of-bounds Read vulnerability in Apache Thrift. This issue affects Apache Thrift: before 0.23.0. Users are recommended to upgrade to version 0.23.0, which fixes the issue....
Other 3ds Solidworks Edrawings Vulnerabilities
A Use of Uninitialized Variable vulnerability affecting the EPRT file reading procedure in SOLIDWORKS eDrawings from Release SOLIDWORKS Desktop 2025 through Release SOLIDWORKS Desktop 2026 could allow...
An Out-Of-Bounds Write vulnerability affecting the EPRT file reading procedure in SOLIDWORKS eDrawings from Release SOLIDWORKS Desktop 2025 through Release SOLIDWORKS Desktop 2026 could allow an attac...