CVE-2025-25471

CVSS 3.1 Score 4.3 of 10 (medium)

Details

Published Feb 18, 2025
Updated: Feb 20, 2025
CWE ID 476

Summary

CVE-2025-25471 is a newly disclosed vulnerability affecting FFmpeg, a widely-used multimedia framework. The issue is rooted in the git master version of libavformat/mov.c, which contains a NULL pointer dereference. This vulnerability can be exploited by malicious actors to cause denial-of-service conditions or potentially gain unauthorized access to affected systems. Successful exploitation relies on the attacker being able to force the vulnerable component to process maliciously crafted media files. Users and administrators are strongly encouraged to apply the forthcoming patch to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share