Out-of-Bounds Stack Write Vulnerability in Trimble SketchUp by Trimble
CVE-2013-3664

Currently unrated

Key Information:

Vendor
Google
Status
Vendor
CVE Published:
1 July 2014

Badges

👾 Exploit Exists🟣 EPSS 25%

Summary

Trimble SketchUp versions prior to 2013 (13.0.3689) suffer from a vulnerability that allows remote attackers to exploit a crafted color palette table in a MAC Pict texture. This manipulation triggers an out-of-bounds stack write, making it possible for malicious actors to execute arbitrary code on the affected systems. The issue is compounded by an incomplete fix for a related vulnerability, further increasing the risk for users.

References

EPSS Score

25% chance of being exploited in the next 30 days.

Timeline

  • 🟡

    Public PoC available

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.