Use-After-Free Vulnerability in Trimble SketchUp Viewer File Parsing
CVE-2024-9714

7.8HIGH

Key Information:

Vendor

Trimble

Vendor
CVE Published:
22 November 2024

What is CVE-2024-9714?

A vulnerability exists in the Trimble SketchUp Viewer related to the parsing of SKP files. This flaw arises from insufficient validation of object existence prior to executing operations on those objects. As a result, attackers can exploit this weakness to execute arbitrary code within the context of the current process. The exploitation requires user interaction, as a target must either navigate to a malicious webpage or open a compromised SKP file to trigger the vulnerability.

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

.