CVE-2024-7509Stack-based Buffer Overflow in Sketchup

Severity
7.8HIGHNVD
EPSS
0.7%
top 28.01%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedNov 22
Latest updateNov 23

Description

Trimble SketchUp SKP File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Trimble SketchUp. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of SKP files. The issue results from the lack of proper validation of the length of user-supplied data prior

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages2 packages

CVEListV5trimble/sketchup22.0.354.0
NVDtrimble/sketchup22.0.354.0

🔴Vulnerability Details

2
GHSA
GHSA-rg23-vpf8-9ppw: Trimble SketchUp SKP File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability2024-11-23
CVEList
Trimble SketchUp SKP File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability2024-11-22
CVE-2024-7509 — Stack-based Buffer Overflow in Sketchup | cvebase