Executive brief
SOLIDWORKS Visualize, a professional 3D rendering and visualization tool, contains a critical security flaw. An attacker can exploit this vulnerability to remotely write unauthorized files onto the system hosting the software. This could lead to a complete system takeover, data theft, or significant disruption of business operations.
Technical details
A Path Traversal vulnerability (CWE-22) exists in SOLIDWORKS Visualize within SOLIDWORKS Desktop Releases 2024 through 2026. The flaw allows an unauthenticated attacker to bypass directory restrictions via the network. By submitting specially crafted input, an attacker can write arbitrary files to the underlying server's file system. This can lead to remote code execution if the attacker overwrites critical system files or application binaries. The vulnerability is rated critical with a CVSS score of 9.8 due to the lack of required authentication or user interaction.
Affected products
- Dassault Systèmes SOLIDWORKS Visualize SOLIDWORKS Desktop Release 2024 through 2026
Timeline
- 2026-06-17: disclosed
- 2026-06-17: advisory