Remote Code Execution Vulnerability in Trimble SketchUp Viewer SKP File Parsing
CVE-2024-9727

7.8HIGH

Key Information:

Vendor

Trimble

Vendor
CVE Published:
22 November 2024

What is CVE-2024-9727?

A vulnerability exists in the Trimble SketchUp Viewer that can be exploited via the parsing of SKP files. The issue arises from failing to validate the existence of an object before executing operations on it. This lack of validation creates an opportunity for remote attackers to execute arbitrary code on the affected installations. Users may be compromised if they interact with malicious files or visit malicious web pages. Protective measures should be considered to safeguard against this exploitation.

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

.