Heap-based buffer overflow vulnerability in Assimp prior to 5.4.2 allows local attacker to execute arbitrary code
CVE-2024-40724
7.8HIGH
Summary
A heap-based buffer overflow vulnerability exists in the Assimp software, specifically in versions prior to 5.4.2. This vulnerability enables a local attacker to potentially execute arbitrary code by submitting a specially crafted file that exploits unhandled input processing. Such an exploit could compromise the integrity and security of the system running the affected software, allowing unauthorized code execution that may lead to further attacks or data breaches. Users are urged to upgrade to the latest version to mitigate this risk.
Affected Version(s)
Assimp prior to 5.4.2
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved