Null Pointer Dereference Vulnerability in OGRECave Ogre Software
CVE-2025-11017
Key Information:
Badges
What is CVE-2025-11017?
A vulnerability has been identified in OGRECave Ogre where improper handling of the argument mDefaultLog in the function Ogre::LogManager::stream, located in /ogre/OgreMain/src/OgreLogManager.cpp, can lead to a null pointer dereference. This issue requires local access for exploitation and the details of the exploit are publicly available. It is crucial for users of the affected software versions to review their systems for potential risks and apply necessary mitigations.
Affected Version(s)
Ogre 14.4.0
Ogre 14.4.1
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved