
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-12495 is a heap-based buffer overflow vulnerability in Academy Software Foundation OpenEXR's EXR file parsing component that allows remote attackers to execute arbitrary code. It affects all OpenEXR versions prior to 3.4.3. The vulnerability was reported to the vendor on September 25, 2025, and publicly disclosed on November 11, 2025, via a coordinated Zero Day Initiative advisory (ZDI-25-989). It carries a CVSS v3.0 base score of 7.8 (High) (ZDI Advisory, Red Hat Bugzilla).
The root cause is classified as CWE-122 (Heap-based Buffer Overflow): the OpenEXR library fails to properly validate the length of user-supplied data before copying it into a heap-allocated buffer during EXR file parsing. An attacker crafts a malicious EXR file with oversized data fields that trigger the overflow when the file is opened by an application using the vulnerable library. Exploitation requires local access in the sense that the attacker must deliver the malicious file to the target (e.g., via a malicious web page or email attachment), and the target user must open it — no authentication or elevated privileges are required on the attacker's side. The vulnerability was originally tracked as ZDI-CAN-27946 and was credited to an anonymous researcher (ZDI Advisory).
Successful exploitation allows an attacker to execute arbitrary code in the context of the process that opens the malicious EXR file, resulting in high confidentiality, integrity, and availability impact on the affected system. This could lead to full compromise of the user's session, unauthorized access to sensitive data, or destruction of data. Because OpenEXR is widely used in media, VFX, and creative software pipelines, the blast radius extends to any application that embeds the library for image processing (ZDI Advisory, Red Hat Bugzilla).
There is no public proof-of-concept exploit code available, and no evidence of in-the-wild exploitation has been observed as of the time of this report. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.042%, indicating a low probability of near-term exploitation. Exploitation requires user interaction — the target must open a specially crafted EXR file — which somewhat limits opportunistic attack scenarios (ZDI Advisory, Red Hat Bugzilla).
.exr files in download directories, temporary folders, or email attachment staging areas; newly created or modified executables or scripts in user-writable directories following EXR file access.bash, cmd.exe, powershell, curl, wget) immediately after opening an EXR file; crashes or abnormal termination of applications using OpenEXR.The vulnerability is fixed in OpenEXR version 3.4.3. Users and administrators should upgrade to this version immediately. As a workaround where upgrading is not immediately possible, restrict the opening of EXR files from untrusted or unknown sources, implement application whitelisting to limit which processes can open EXR files, and use sandboxing for applications that process untrusted image files. Patches are also available through Linux distribution channels including Red Hat and Fedora (ZDI Advisory, Red Hat Bugzilla).
The vulnerability was disclosed through the Zero Day Initiative's coordinated disclosure process and credited to an anonymous researcher. Red Hat has tracked the issue in its Bugzilla system with high severity and priority, and Fedora package updates for openexr and mingw-openexr have been issued. No notable public researcher commentary or significant social media discussion has been identified beyond standard vulnerability aggregator coverage (ZDI Advisory, Red Hat Bugzilla).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."