Remote Code Execution in Trimble SketchUp Due to SKP File Parsing Flaw
CVE-2025-2024

7.8HIGH

Key Information:

Vendor

Trimble

Status
Vendor
CVE Published:
7 March 2025

What is CVE-2025-2024?

A vulnerability in Trimble SketchUp exists when the application improperly parses SKP files due to an uninitialized variable. This flaw allows remote attackers to execute arbitrary code if a user interacts with a malicious file or webpage. The vulnerability exploits the lack of secure memory initialization before access, enabling attackers to manipulate code execution within the context of the application.

Affected Version(s)

SketchUp 2024-0-484-191

References

CVSS V3.0

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.