CVE-2025-3015

CVSS 3.1 Score 8.6 of 10 (high)

Details

Published Mar 31, 2025
Updated: Apr 17, 2025
CWE ID 506

Summary

CVE-2025-3015 is a critical vulnerability identified in Open Asset Import Library Assimp 5.4.3. This issue lies within the Assimp::ASEImporter::BuildUniqueRepresentation function of the ASE File Handler's ASELoader.cpp file. Malicious manipulation of the mIndices argument results in an out-of-bounds read, enabling remote attacks. The exploit for this vulnerability has been made public, increasing the risk. Upgrading to Assimp version 6.0 or applying the patch with the commit hash 7c705fde418d68cca4e8eff56be01b2617b0d6fe is recommended to mitigate this issue.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share