Junglewise Threat Intelligence

CVE-2025-60749: Trimble SketchUp Desktop DLL hijacking in sketchup_webhelper.exe

CVE-2025-60749 · Severity: high · CVSS 7.8 · Published 2025-10-31

Vendors: Trimble.

Executive brief

Trimble SketchUp Desktop 2025, a popular 3D modeling software, is vulnerable to a security flaw that allows an attacker to take control of a user's computer. By placing a specially crafted file in a specific folder, an attacker can trick the software into running malicious code when it starts. This could lead to the theft of sensitive data, unauthorized access to the system, or the installation of persistent malware.

Technical details

A DLL hijacking vulnerability exists in Trimble SketchUp Desktop 2025 due to an uncontrolled search path (CWE-427) in the sketchup_webhelper.exe process. The application attempts to load libcef.dll without specifying a fully qualified path, allowing an attacker with local access to place a malicious version of the DLL in a higher-priority directory. When the application or the web helper process starts, it loads the attacker's DLL, enabling arbitrary code execution with the privileges of the running user. This can be used to establish persistence or deploy remote access tools like Cobalt Strike.

Affected products

  • Trimble SketchUp Desktop 2025

Timeline

  • 2025-10-23: disclosed: Initial vulnerability report and PoC published by researcher.
  • 2025-10-31: advisory: CVE-2025-60749 published.

References

Related threats