CVE-2025-2592

CVSS 3.1 Score 8 of 10 (high)

Details

Published Mar 21, 2025
CWE ID 352

Summary

CVE-2025-2592 is a critical vulnerability affecting Open Asset Import Library Assimp 5.4.3. The issue resides in the CSMImporter::InternReadFile function of the file CSM/CSMLoader.cpp. This vulnerability results in a heap-based buffer overflow, making it susceptible to remote exploitation. The exploit has been made public, posing a significant risk. To mitigate this threat, it is strongly advised to install the patch, which carries the commit hash 2690e354da0c681db000cfd892a55226788f2743.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share