ZDI-CAN-19112: ZDI-24-187: Trimble SketchUp SKP File Parsing Use-After-Free Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Trimble SketchUp. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-19112?
ZDI-CAN-19112 has been assigned a CVSS rating indicating its potential impact on system security.
How do I fix ZDI-CAN-19112?
To fix ZDI-CAN-19112, update Trimble SketchUp to the latest version which addresses this vulnerability.
What types of attacks can exploit ZDI-CAN-19112?
ZDI-CAN-19112 can be exploited by remote attackers to execute arbitrary code through a malicious page or file.
Is user interaction required to exploit ZDI-CAN-19112?
Yes, user interaction is required as the target must visit a malicious page or open a malicious file for the exploitation.
Which software is affected by ZDI-CAN-19112?
ZDI-CAN-19112 affects installations of Trimble SketchUp, particularly Trimble SketchUp Pro.