CVE-2025-11275 describes a heap-based buffer overflow vulnerability in Open Asset Import Library (Assimp) version 6.0.2, specifically within the ODDLParser::getNextSeparator function. This high-severity flaw (CVSS 7.8) can lead to complete compromise of confidentiality, integrity, and availability if exploited. Exploitation requires local access and low privileges, but does not necessitate user interaction. While an exploit is publicly available, there is currently no evidence of active exploitation, and it has garnered minimal community discussion or media attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
6.0.2CPE matchmatch criteria | cpe:2.3:a:assimp:assimp:6.0.2:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.