TL;DR

A remote code execution vulnerability in Dassault Systèmes eDrawings Viewer allows attackers to execute arbitrary code via malicious EPRT files or web pages.

What happened

['Remote code execution vulnerability in eDrawings Viewer', 'EPRT file parsing issue leads to out-of-bounds write']

Why it matters for ops

['User interaction required for exploit', 'High CVSS score indicating significant risk']

Mitigation

  • Update to the latest version of eDrawings Viewer
  • Disable opening EPRT files from untrusted sources

Action items

  • Install available software updates
  • Monitor for unusual activity

Detection IOCs

  • Unusual network traffic patterns
  • Unexpected system crashes or hangs

Source link

http://www.zerodayinitiative.com/advisories/ZDI-26-095/