Executive brief
SOLIDWORKS Desktop, a widely used computer-aided design (CAD) application, is affected by a security flaw that could allow an attacker to take control of a user's computer. By tricking a user into opening a specially crafted design file, an attacker can execute malicious commands. This could lead to the theft of sensitive engineering data, unauthorized access to corporate systems, or a complete compromise of the workstation.
Technical details
A Code Injection vulnerability (CWE-94) exists in Dassault Systèmes SOLIDWORKS Desktop versions 2025 through 2026. The flaw is triggered when the application processes a specially crafted file, leading to improper control of code generation. This is a local attack vector that requires user interaction, specifically the opening of a malicious file by the victim. Successful exploitation allows an attacker to execute arbitrary code with the privileges of the current user, potentially leading to full system compromise. The vulnerability was disclosed by the vendor on March 16, 2026.
Affected products
- Dassault Systèmes SOLIDWORKS Desktop 2025 through 2026
Timeline
- 2026-03-16: disclosed: Initial advisory published by Dassault Systèmes
- 2026-03-16: advisory: CVE-2026-3476 published to NVD