Memory Corruption Vulnerability in Trimble SketchUp Viewer SKP File Parsing
CVE-2024-9730

7.8HIGH

Key Information:

Vendor

Trimble

Status
Vendor
CVE Published:
22 November 2024

What is CVE-2024-9730?

A memory corruption vulnerability exists in the Trimble SketchUp Viewer relating to the parsing of SKP files. This flaw arises due to inadequate validation of user-supplied data, which can lead to a condition allowing attackers to execute arbitrary code. To exploit this vulnerability, user interaction is necessary, as the target must either visit a malicious webpage or open a compromised file. Successful exploitation gives attackers the ability to execute code in the context of the affected process, posing significant security risks to users of the software.

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

.
CVE-2024-9730 : Memory Corruption Vulnerability in Trimble SketchUp Viewer SKP File Parsing