Remote Code Execution Vulnerability in Trimble SketchUp Viewer
CVE-2024-9717

7.8HIGH

Key Information:

Vendor

Trimble

Vendor
CVE Published:
22 November 2024

What is CVE-2024-9717?

The Trimble SketchUp Viewer is affected by a vulnerability related to the parsing of SKP files, which allows remote attackers to execute arbitrary code on affected installations. The vulnerability arises from the improper initialization of memory, allowing attackers to exploit this flaw under specific conditions. User interaction is essential as this exploitation requires the target to either visit a malicious website or open a compromised SKP file. Successfully leveraging this weakness can enable the execution of code within the process context of the user, posing significant risks to system integrity and data security.

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

.