Use-After-Free Vulnerability in Trimble SketchUp Viewer SKP File Parsing
CVE-2023-50191

Currently unrated

Key Information:

Vendor

Trimble

Vendor
CVE Published:
3 May 2024

What is CVE-2023-50191?

A vulnerability in Trimble SketchUp Viewer arises due to improper validation during SKP file parsing, leading to a use-after-free condition. This flaw allows remote attackers to execute arbitrary code within the context of the current process by enticing users to open a crafted file or visit a malicious webpage. Because user interaction is required, this vulnerability poses risks primarily when users engage with untrusted content.

References

Timeline

  • Vulnerability published

.
CVE-2023-50191 : Use-After-Free Vulnerability in Trimble SketchUp Viewer SKP File Parsing