PT-2025-12784 · Assimp+1 · Assimp+1

D3Ng03

·

Published

2025-03-25

·

Updated

2026-03-20

·

CVE-2025-2754

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Open Asset Import Library Assimp version 5.4.3
Description A critical issue has been identified in the AC3D File Handler component, specifically in the function Assimp::AC3DImporter::ConvertObjectSection of the file code/AssetLib/AC/ACLoader.cpp. The manipulation of the it argument leads to a heap-based buffer overflow. This issue can be exploited remotely.
Recommendations For Open Asset Import Library Assimp version 5.4.3, consider disabling the Assimp::AC3DImporter::ConvertObjectSection function until a patch is available to prevent heap-based buffer overflow exploitation. Restrict access to the AC3D File Handler component to minimize the risk of remote attacks.

Exploit

Fix

Heap Based Buffer Overflow

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-2754
OESA-2026-1330
OESA-2026-1331
OESA-2026-1659
PYSEC-2025-165

Affected Products

Assimp
Debian