CVE-2026-1334
Out-Of-Bounds Read in SOLIDWORKS eDrawings EPRT Leads to RCE
Publication date: 2026-02-16
Last updated on: 2026-02-26
Assigner: Dassault Systèmes
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| 3ds | solidworks_edrawings | 2025 |
| 3ds | solidworks_edrawings | 2025 |
| 3ds | solidworks_edrawings | 2025 |
| 3ds | solidworks_edrawings | 2025 |
| 3ds | solidworks_edrawings | 2025 |
| 3ds | solidworks_edrawings | 2025 |
| 3ds | solidworks_edrawings | 2026 |
| 3ds | solidworks_edrawings | 2026 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-125 | The product reads data past the end, or before the beginning, of the intended buffer. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
CVE-2026-1334 is a high-severity Out-Of-Bounds Read vulnerability in the EPRT file reading procedure of SOLIDWORKS eDrawings, affecting versions from SOLIDWORKS Desktop 2025 through SOLIDWORKS Desktop 2026.
This vulnerability occurs due to improper handling of data during the parsing of EPRT files, which leads to an out-of-bounds read condition.
An attacker can exploit this by crafting a malicious EPRT file that, when opened, allows the attacker to execute arbitrary code on the affected system.
How can this vulnerability impact me? :
This vulnerability can have serious impacts as it allows an attacker to execute arbitrary code on your system by opening a specially crafted EPRT file.
- Execution of arbitrary code could lead to unauthorized control over the affected system.
- Potential compromise of system confidentiality, integrity, and availability.
- Possible data breaches, system disruptions, or further malware installation.
How does this vulnerability affect compliance with common standards and regulations (like GDPR, HIPAA)?:
I don't know
How can this vulnerability be detected on my network or system? Can you suggest some commands?
I don't know
What immediate steps should I take to mitigate this vulnerability?
I don't know