Use-After-Free Vulnerability in Trimble SketchUp Viewer
CVE-2024-9725

7.8HIGH

Key Information:

Vendor

Trimble

Vendor
CVE Published:
22 November 2024

What is CVE-2024-9725?

A vulnerability in Trimble SketchUp Viewer arises from improper handling of SKP file parsing, leading to a use-after-free condition. This security flaw allows remote attackers to execute arbitrary code against installations of the application. The exploitation of this vulnerability requires user interaction, as it necessitates opening a specially crafted SKP file or visiting a malicious webpage. The lack of validation that an object exists before performing operations on it is the core issue that enables this exploit, potentially compromising the user's system and data integrity.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

.