Use-After-Free Remote Code Execution Vulnerability in Trimble SketchUp Viewer
CVE-2024-9716

7.8HIGH

Key Information:

Vendor

Trimble

Vendor
CVE Published:
22 November 2024

What is CVE-2024-9716?

A use-after-free vulnerability exists in the Trimble SketchUp Viewer that can be exploited via the parsing of SKP files. Attackers can execute arbitrary code on affected installations if a user interacts with a malicious page or file. This flaw arises from the failure to verify the presence of an object before executing operations on it, enabling unauthorized code execution within the context of the current process. Users are advised to exercise caution when handling unknown SKP files or visiting untrusted web pages.

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

.