CVE-2025-15062

7.8

Trimble · SketchUp

A use-after-free vulnerability in the Trimble SketchUp SKP file parser allows remote code execution via a specially crafted file.

Executive summary

A critical use-after-free vulnerability in Trimble SketchUp version 25.0.660 could allow an unauthenticated attacker to execute arbitrary code on the host system.

Vulnerability

This vulnerability is a use-after-free flaw (CWE-416) within the SKP file parsing logic. An attacker can trigger this vulnerability when a user opens a malicious file, leading to code execution in the context of the current process.

Business impact

Successful exploitation of this vulnerability allows for remote code execution, which can lead to complete system compromise, data theft, or the installation of persistent malware. With a CVSS score of 7.8, this flaw represents a significant risk to operational integrity, particularly in environments where SketchUp is used to process files from untrusted external sources.

Remediation

Immediate Action: Update Trimble SketchUp to the latest version provided by the vendor to address the underlying memory corruption flaw.

Proactive Monitoring: Monitor endpoint activity for unexpected child processes spawned by the SketchUp application or abnormal memory usage patterns during file import operations.

Compensating Controls: Implement strict file access policies and ensure that users only open SketchUp files from trusted, verified sources to limit exposure to malicious payloads.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

Given the potential for remote code execution and the nature of the flaw, organizations should prioritize patching all systems running the affected version of Trimble SketchUp. Users should be advised to exercise caution when handling SKP files from unknown or unverified origin until the update is successfully applied across the environment.

More Trimble CVEs

Sources