CVE-2026-1333
Received
Received - Intake
Use of Uninitialized Variable in SOLIDWORKS eDrawings EPRT Leads to RCE
Publication date: 2026-02-16
Last updated on: 2026-02-26
Assigner: Dassault Systèmes
Description
Description
A Use of Uninitialized Variable vulnerability affecting the EPRT file reading procedure in SOLIDWORKS eDrawings from Release SOLIDWORKS Desktop 2025 through Release SOLIDWORKS Desktop 2026 could allow an attacker to execute arbitrary code while opening a specially crafted EPRT file.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| 3ds | solidworks_edrawings | 2025 |
| 3ds | solidworks_edrawings | 2025 |
| 3ds | solidworks_edrawings | 2025 |
| 3ds | solidworks_edrawings | 2025 |
| 3ds | solidworks_edrawings | 2025 |
| 3ds | solidworks_edrawings | 2025 |
| 3ds | solidworks_edrawings | 2026 |
| 3ds | solidworks_edrawings | 2026 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-457 | The code uses a variable that has not been initialized, leading to unpredictable or unintended results. |