CVE-2025-60749
7.8Trimble · SketchUp
Trimble SketchUp desktop 2025 is susceptible to a DLL hijacking vulnerability via a crafted libcef.dll file, which can allow an attacker to execute arbitrary code.
Executive summary
A DLL hijacking vulnerability in Trimble SketchUp 2025 poses a high risk of local code execution for users on affected systems.
Vulnerability
The application is vulnerable to DLL hijacking through the sketchup_webhelper.exe process, which loads a malicious libcef.dll file. This attack requires local access and low privileges, as indicated by the CVSS vector (AV:L/PR:L/UI:N).
Business impact
The vulnerability carries a CVSS score of 7.8, representing a High severity risk. Successful exploitation allows a local attacker to execute arbitrary code with the privileges of the SketchUp application, potentially leading to full system compromise, unauthorized data access, or the deployment of persistent malware within the internal environment.
Remediation
Immediate Action: Check the official Trimble SketchUp help and download pages for security patches or updated versions of the desktop software.
Proactive Monitoring: Monitor local system logs for unauthorized file modifications or the execution of unexpected DLLs within the SketchUp installation directory.
Compensating Controls: Implement strict file system permissions on the SketchUp installation folder to prevent unauthorized users from replacing legitimate application binaries or DLLs.
Exploitation status
Public Exploit Available: Yes, a public proof-of-concept exists via the GitHub repository referenced in the researcher write-up at yawataa.github.io.
Analyst recommendation
This vulnerability presents a significant risk to local system integrity. Administrators should prioritize identifying all instances of SketchUp 2025 within their environment and prepare to apply vendor-supplied updates as soon as they are released. Until a patch is confirmed, restrict local access to the application directory to minimize the window of opportunity for local attackers.