CVE-2025-11277

⚪ Do wiadomości

Przepełnienie bufora w Open Asset Import Library umożliwia lokalne wykonanie kodu.

CVSS
5.3
EPSS
0.2%
Exploit
poc
Vendor
assimp
Opis źródłowy (NVD)

A weakness has been identified in Open Asset Import Library Assimp 6.0.2. This affects the function Q3DImporter::InternReadFile of the file assimp/code/AssetLib/Q3D/Q3DLoader.cpp. Executing a manipulation can lead to heap-based buffer overflow. The attack needs to be launched locally. The exploit has been made available to the public and could be used for attacks.

buffer-overflow exploit Brak patcha
Źródła i daty
ŹródłoWartość
NVD – CVSS5.3
CISA KEV (aktywnie wykorzystywane)Nie
FIRST EPSS (prawdopodobieństwo exploita)0.2%
Opublikowano (NVD)2025-10-05 02:15:37 UTC
Ostatnia modyfikacja (NVD)2026-10-08 22:10:00 UTC
Referencje