Out-of-bounds Read in Open Asset Import Library Assimp Affects Local Functionality
CVE-2025-5201
4.8MEDIUM
Key Information:
- Vendor
Open Asset Import Library
- Status
- Vendor
- CVE Published:
- 26 May 2025
Badges
👾 Exploit Exists🟡 Public PoC
What is CVE-2025-5201?
A local vulnerability has been identified in the Open Asset Import Library Assimp version 5.4.3, specifically in the LWOImporter::CountVertsAndFacesLWO2 function found in the LWOLoader.cpp file. This issue allows for potential out-of-bounds reads, which may expose sensitive information during processing. The exploit, having been made public, emphasizes the need for immediate attention and resolution by the developers. This falls within a broader initiative to address various Fuzzer-stated bugs systematically.
Affected Version(s)
Assimp 5.4.3
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.