ZDI-CAN-18983: ZDI-24-190: Trimble SketchUp SKP File Parsing Use-After-Free Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Trimble SketchUp. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-18983?
ZDI-CAN-18983 has a CVSS rating indicating a significant risk due to the potential for remote code execution.
How do I fix ZDI-CAN-18983?
To mitigate ZDI-CAN-18983, users should update Trimble SketchUp to the latest version that addresses this vulnerability.
What type of attack vector is used in ZDI-CAN-18983?
ZDI-CAN-18983 is exploited via user interaction, requiring the target to visit a malicious page or open a malicious file.
Who is affected by ZDI-CAN-18983?
Users of Trimble SketchUp Pro are affected by ZDI-CAN-18983.
What is the potential impact of ZDI-CAN-18983?
The impact of ZDI-CAN-18983 could allow remote attackers to execute arbitrary code on vulnerable systems.