Remote Code Execution in Trimble SketchUp Due to SKP File Parsing Flaw
CVE-2025-2024
7.8HIGH
What is CVE-2025-2024?
A vulnerability in Trimble SketchUp exists when the application improperly parses SKP files due to an uninitialized variable. This flaw allows remote attackers to execute arbitrary code if a user interacts with a malicious file or webpage. The vulnerability exploits the lack of secure memory initialization before access, enabling attackers to manipulate code execution within the context of the application.
Affected Version(s)
SketchUp 2024-0-484-191