Description
Heap-based Buffer Overflow and Uninitialized Variable vulnerabilities exist in the X_B and SAT file reading procedure in eDrawings from Release SOLIDWORKS 2024 through Release SOLIDWORKS 2025. These vulnerabilities could allow an attacker to execute arbitrary code while opening a specially crafted X_B or SAT file.
Problem types
CWE-122 Heap-based Buffer Overflow
CWE-457: Use of Uninitialized Variable
Product status
Release SOLIDWORKS 2024 SP0 (custom)
Release SOLIDWORKS 2025 SP0
Credits
Mat Powell of Trend Micro Zero Day Initiative
Andrea Micalizzi aka rgod (@rgod777) working with Trend Micro Zero Day Initiative
References
www.3ds.com/vulnerability/advisories