Remote Code Execution Vulnerability in Trimble SketchUp Viewer
CVE-2024-9723

7.8HIGH

Key Information:

Vendor

Trimble

Vendor
CVE Published:
22 November 2024

What is CVE-2024-9723?

A remote code execution vulnerability exists in the Trimble SketchUp Viewer due to improper handling of SKP file parsing. This flaw can be exploited by an attacker when a user interacts with a malicious page or opens a specially crafted SKP file. The vulnerability is rooted in the failure to properly validate the existence of an object before executing operations on it, potentially leading to execution of arbitrary code within the context of the current process. Vigilance and caution are essential when interacting with untrusted files or sources.

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

.