CVE-2024-3299: 3ds Edrawings

High severity, CVSS 7.8. EPSS: 0.4% chance of exploitation in the next 30 days.

Out-Of-Bounds Write, Use of Uninitialized Resource and Use-After-Free vulnerabilities exist in the file reading procedure in eDrawings from Release SOLIDWORKS 2023 through Release SOLIDWORKS 2024. These vulnerabilities could allow an attacker to execute arbitrary code while opening a specially crafted SLDDRW or SLDPRT file. NOTE: this vulnerability was SPLIT from CVE-2024-1847.

Affected products

  • 3ds Edrawings: from 2023, up to and including 2023_sp5; from 2024, up to and including 2024_sp1
  • Dassault Systèmes Edrawings

Published 2024-04-04. Last modified 2026-06-17.