ZDI-24-190: Trimble SketchUp SKP File Parsing Use-After-Free Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Trimble SketchUp. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-24-190?
ZDI-24-190 has a CVSS rating indicating a high severity due to the potential for remote code execution.
How do I fix ZDI-24-190?
To fix ZDI-24-190, users should update to the latest version of Trimble SketchUp that addresses this vulnerability.
What types of attacks can leverage ZDI-24-190?
ZDI-24-190 can be exploited by remote attackers through malicious web pages or files that require user interaction.
Are there any workarounds for ZDI-24-190?
As a workaround for ZDI-24-190, users should avoid opening unknown or suspicious files and links related to Trimble SketchUp.
Who is affected by ZDI-24-190?
Users of Trimble SketchUp Pro are affected by the ZDI-24-190 vulnerability.