Memory Corruption Issue in Trimble SketchUp Viewer SKP File Parsing
CVE-2024-9731

7.8HIGH

Key Information:

Vendor

Trimble

Vendor
CVE Published:
22 November 2024

What is CVE-2024-9731?

A vulnerability exists in the Trimble SketchUp Viewer related to the processing of SKP files that can lead to memory corruption. This flaw arises from insufficient validation of user-supplied data, enabling malicious entities to execute arbitrary code on systems running the affected software. Successful exploitation requires user interaction to visit a malicious website or to open a compromised SKP file. Addressing this issue is essential to safeguard user environments from potential threats and to maintain the integrity of the software.

Affected Version(s)

SketchUp Viewer 22.0.316.0

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

CVSS V3.0

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

.