ZDI-CAN-19114: ZDI-24-188: Trimble SketchUp SKP File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Trimble SketchUp. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-19114?
The ZDI-CAN-19114 vulnerability has been assigned a CVSS rating indicating a critical severity level.
How do I fix ZDI-CAN-19114?
To mitigate ZDI-CAN-19114, ensure that you update Trimble SketchUp to the latest version provided by the vendor.
What are the attack vectors for ZDI-CAN-19114?
ZDI-CAN-19114 can be exploited by remote attackers through a malicious page or file that requires user interaction.
Who is affected by ZDI-CAN-19114?
ZDI-CAN-19114 affects users of Trimble SketchUp, specifically those using vulnerable versions of the software.
What type of vulnerability is ZDI-CAN-19114?
ZDI-CAN-19114 is a remote code execution vulnerability allowing attackers to execute arbitrary code on affected systems.