Null Pointer Dereference in Poco v1.14.1 by Applied Informatics
CVE-2025-6375
Key Information:
- Vendor
Applied Informatics
- Status
- Vendor
- CVE Published:
- 21 June 2025
Badges
What is CVE-2025-6375?
A vulnerability has been identified in Poco versions up to 1.14.1, specifically within the MultipartInputStream function in the MultipartReader.cpp file. This issue allows for a null pointer dereference, which can lead to unexpected application behavior. The exploit requires local access to the affected application, and details of the vulnerability have been publicly disclosed, allowing potential misuse. To mitigate the risks associated with this vulnerability, users are strongly advised to upgrade to version 1.14.2, which includes an essential patch addressing this issue.
Affected Version(s)
poco 1.14.0
poco 1.14.1
poco 1.14.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved