CVE-2025-2584

CVSS 3.1 Score 7.4 of 10 (high)

Details

Published Mar 21, 2025
Updated: Mar 24, 2025
CWE ID 119
CWE ID 787
CWE ID 122

Summary

CVE-2025-2584 is a critical vulnerability affecting WebAssembly wabt version 1.0.36. This issue lies within the BinaryReaderInterp::GetReturnCallDropKeepCount function of the file wabt/src/interp/binary-reader-interp.cc. The flaw results in a heap-based buffer overflow, allowing an attacker to initiate remote exploits. The complexity of an attack is relatively high, and exploitation is reportedly difficult, but the vulnerability has been publicly disclosed, increasing the risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share