{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-09-22T14:16:27.951","vulnerabilities":[{"cve":{"id":"CVE-2024-3299","sourceIdentifier":"3DS.Information-Security@3ds.com","published":"2024-04-04T15:15:40.197","lastModified":"2026-06-17T07:43:44.497","vulnStatus":"Deferred","cveTags":[],"descriptions":[{"lang":"en","value":"Out-Of-Bounds Write, Use of Uninitialized Resource and Use-After-Free vulnerabilities exist in the file reading procedure in eDrawings from Release SOLIDWORKS 2023 through Release SOLIDWORKS 2024. These vulnerabilities could allow an attacker to execute arbitrary code while opening a specially crafted SLDDRW or SLDPRT file. NOTE: this vulnerability was SPLIT from CVE-2024-1847."},{"lang":"es","value":"Existen vulnerabilidades de escritura fuera de los límites, uso de recursos no inicializados y uso después de la liberación en el procedimiento de lectura de archivos en eDrawings desde la versión SOLIDWORKS 2023 hasta la versión SOLIDWORKS 2024. Estas vulnerabilidades podrían permitir a un atacante ejecutar código arbitrario al abrir un archivo especialmente manipulado. Archivo SLDDRW o SLDPRT. NOTA: esta vulnerabilidad fue DIVIDIDA de CVE-2024-1847."}],"affected":[{"source":"3DS.Information-Security@3ds.com","affectedData":[{"vendor":"Dassault Systèmes","product":"eDrawings","defaultStatus":"unaffected","versions":[{"version":"Release SOLIDWORKS 2023 SP0","lessThanOrEqual":"Release SOLIDWORKS 2023 SP5","versionType":"custom","status":"affected"},{"version":"Release SOLIDWORKS 2024 SP0","lessThanOrEqual":"Release SOLIDWORKS 2024 SP1","versionType":"custom","status":"affected"}]}]},{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","affectedData":[{"vendor":"3ds","product":"edrawings","defaultStatus":"unaffected","cpes":["cpe:2.3:a:3ds:edrawings:2023:sp0:*:*:*:*:*:*"],"versions":[{"version":"2023","lessThanOrEqual":"2023_sp5","versionType":"custom","status":"affected"}]},{"vendor":"3ds","product":"edrawings","defaultStatus":"unaffected","cpes":["cpe:2.3:a:3ds:edrawings:2024:sp0:*:*:*:*:*:*"],"versions":[{"version":"2024","lessThanOrEqual":"2024_sp1","versionType":"custom","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"3DS.Information-Security@3ds.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2024-07-25T20:16:37.735661Z","id":"CVE-2024-3299","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"3DS.Information-Security@3ds.com","type":"Secondary","description":[{"lang":"en","value":"CWE-416"},{"lang":"en","value":"CWE-787"},{"lang":"en","value":"CWE-908"}]}],"references":[{"url":"https://www.3ds.com/vulnerability/advisories","source":"3DS.Information-Security@3ds.com"},{"url":"https://www.3ds.com/vulnerability/advisories","source":"af854a3a-2127-422b-91ae-364da2661108"}]}}]}