Out-of-bounds Read in Open Asset Import Library Assimp Affects Local Functionality
CVE-2025-5201

4.8MEDIUM

Key Information:

Status
Vendor
CVE Published:
26 May 2025

Badges

👾 Exploit Exists🟡 Public PoC

What is CVE-2025-5201?

A local vulnerability has been identified in the Open Asset Import Library Assimp version 5.4.3, specifically in the LWOImporter::CountVertsAndFacesLWO2 function found in the LWOLoader.cpp file. This issue allows for potential out-of-bounds reads, which may expose sensitive information during processing. The exploit, having been made public, emphasizes the need for immediate attention and resolution by the developers. This falls within a broader initiative to address various Fuzzer-stated bugs systematically.

Affected Version(s)

Assimp 5.4.3

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

CVSS V4

Score:
4.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • 🟡

    Public PoC available

  • 👾

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-5201 : Out-of-bounds Read in Open Asset Import Library Assimp Affects Local Functionality