Remote Code Execution Vulnerability in Trimble SketchUp Viewer SKP File Parsing
CVE-2023-50189

7.8HIGH

Key Information:

Vendor

Trimble

Vendor
CVE Published:
3 May 2024

What is CVE-2023-50189?

A remote code execution vulnerability has been identified in the Trimble SketchUp Viewer related to the parsing of SKP files. The issue arises due to insufficient validation of object existence before certain operations are conducted. An attacker can exploit this flaw when a user visits a malicious page or opens a specially crafted SKP file, allowing them to execute arbitrary code within the context of the current process. This exploitation underscores the necessity for users to be cautious about the sources of files and links they open.

Affected Version(s)

SketchUp Viewer 22.0.354

References

CVSS V3.0

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

.