CVE-2024-3298
Last modified
CVE-2024-3298 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. Out-Of-Bounds Write and Type Confusion vulnerabilities exist in the file reading procedure in eDrawings from Release SOLIDWORKS 2023 through Release SOLIDWORKS 2024. These vulnerabilities could allow an attacker to execute arbitrary code while opening a specially crafted DWG or DXF. EPSS estimates a 0.32% chance of exploitation in the next 30 days.
Description
Out-Of-Bounds Write and Type Confusion vulnerabilities exist in the file reading procedure in eDrawings from Release SOLIDWORKS 2023 through Release SOLIDWORKS 2024. These vulnerabilities could allow an attacker to execute arbitrary code while opening a specially crafted DWG or DXF. NOTE: this vulnerability was SPLIT from CVE-2024-1847.
Metrics
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2024-3298?
How severe is CVE-2024-3298?
How do I fix CVE-2024-3298?
Are you affected by CVE-2024-3298?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
