PT-2024-16117 · Solidworks · Edrawings

Mat Powell

·

Published

2024-11-19

·

Updated

2024-11-19

·

CVE-2024-10204

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions eDrawings versions Release SOLIDWORKS 2024 through Release SOLIDWORKS 2025
Description The issue is related to Heap-based Buffer Overflow and Uninitialized Variable vulnerabilities in the X B and SAT file reading procedure. These vulnerabilities could allow an attacker to execute arbitrary code while opening a specially crafted X B or SAT file.
Recommendations For versions Release SOLIDWORKS 2024 through Release SOLIDWORKS 2025, update to a version that contains a fix for this issue, as the current version may allow an attacker to execute arbitrary code. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Heap Based Buffer Overflow

Weakness Enumeration

Related Identifiers

CVE-2024-10204
ZDI-24-1528
ZDI-24-1529

Affected Products

Edrawings