CVE-2025-2755

CVSS 3.1 Score 9.9 of 10 (high)

Details

Published Mar 25, 2025
Updated: Mar 27, 2025
CWE ID 94

Summary

CVE-2025-2755 is a critical vulnerability affecting Open Asset Import Library Assimp 5.4.3. This issue lies within the Assimp::AC3DImporter::ConvertObjectSection function in the file code/AssetLib/AC/ACLoader.cpp, specifically with the component AC3D File Handler. The flaw involves an out-of-bounds read, which can be triggered by manipulating the argument src.entries. This vulnerability can be exploited remotely and the exploit has been made public, posing a significant risk to systems utilizing this software version.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share