CVE-2025-2591

CVSS 3.1 Score 9.8 of 10 (high)

Details

Published Mar 21, 2025
CWE ID 89

Summary

CVE-2025-2591 is a newly disclosed vulnerability affecting Open Asset Import Library Assimp 5.4.3. The issue lies within the MDLImporter::InternReadFile_Quake1 function in the file code/AssetLib/MDL/MDLLoader.cpp. An attacker can manipulate the argument skinwidth/skinheight, leading to a divide-by-zero error. This vulnerability is remotely exploitable and the exploit has been made public. To mitigate the risk, it is strongly advised to apply the patch, which is identified as ab66a1674fcfac87aaba4c8b900b315ebc3e7dbd.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share