ZDI-24-188: Trimble SketchUp SKP File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
Published Feb 21, 2024
·Updated
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Trimble SketchUp. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8.
Affected Software
1 affected component
Trimble SketchUp
Event History
Feb 21, 2024
Advisory Published
via ZDI·06:00 AM
Data Sourced
via ZDI·06:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-24-188?
The severity of ZDI-24-188 is high due to the potential for remote code execution.
2
How do I fix ZDI-24-188?
To fix ZDI-24-188, update Trimble SketchUp to the latest version released by the vendor.
3
What type of attack is associated with ZDI-24-188?
ZDI-24-188 is associated with remote code execution attacks that require user interaction.
4
Is user interaction required to exploit ZDI-24-188?
Yes, user interaction is required to exploit ZDI-24-188 by visiting a malicious page or opening a malicious file.
5
Which software is affected by ZDI-24-188?
The affected software for ZDI-24-188 is Trimble SketchUp.