Out-Of-Bounds Read Vulnerability in Trimble SketchUp Viewer
CVE-2024-9720

7.8HIGH

Key Information:

Vendor

Trimble

Vendor
CVE Published:
22 November 2024

What is CVE-2024-9720?

A vulnerability exists in the Trimble SketchUp Viewer that pertains to the parsing of SKP files. This flaw arises due to insufficient validation of data supplied by users, which can lead to a read beyond the allocated buffer's limit. Attackers can exploit this vulnerability by enticing users to open a specially crafted SKP file or visit a malicious web page, potentially allowing arbitrary code execution within the context of the running process. It is crucial for users of affected versions to be aware of this risk and implement necessary safeguards.

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

.