
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-12840 is a heap-based buffer overflow vulnerability in Academy Software Foundation OpenEXR that allows remote attackers to execute arbitrary code on affected installations. The flaw exists within the parsing of EXR files, where user-supplied data length is not properly validated before being copied to a heap-based buffer. It affects all OpenEXR versions prior to 3.4.3. The vulnerability was reported to the vendor on 2025-09-25 and publicly disclosed on 2025-11-11 via a coordinated ZDI advisory (ZDI-25-991). It carries a CVSS v3.0 base score of 7.8 (High) (ZDI Advisory, Red Hat CVE).
The root cause is classified as CWE-122 (Heap-based Buffer Overflow), arising from insufficient validation of the length of user-supplied data during EXR file parsing before it is copied into a heap-allocated buffer. An attacker crafts a malicious EXR file (or hosts it on a malicious web page) and tricks a target user into opening it; the oversized data then overflows the heap buffer, potentially allowing control of program execution flow. Exploitation requires local access in the sense that the file must be opened by the target process, but the attack can be initiated remotely by delivering the malicious file. The vulnerability was tracked internally by ZDI as ZDI-CAN-27948 (ZDI Advisory, Red Hat Bugzilla).
Successful exploitation allows an attacker to execute arbitrary code in the context of the process that opens the malicious EXR file, resulting in high confidentiality, integrity, and availability impact on the affected system. This could lead to full compromise of the user's session, data exfiltration, or installation of malware. Applications and workflows that automatically process or preview EXR files (e.g., media pipelines, VFX tools, image viewers) are at elevated risk due to reduced user interaction requirements in automated contexts (ZDI Advisory, Red Hat CVE).
User interaction is required — the target must open a malicious EXR file or visit a page that triggers EXR parsing. No public proof-of-concept exploit code has been identified, and there is no evidence of in-the-wild exploitation or threat actor attribution at this time. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.042%, indicating a low current probability of exploitation in the wild (ZDI Advisory, Red Hat CVE).
.exr files in user download directories, temp folders, or media processing input directories; new or modified executables/scripts created shortly after EXR file access.bash, cmd.exe), network utilities (curl, wget), or scripting interpreters.The vendor has released OpenEXR v3.4.3, which fixes this vulnerability. Users and administrators should upgrade all installations of OpenEXR to version 3.4.3 or later as the primary remediation (ZDI Advisory). As a workaround where immediate patching is not possible, restrict the processing of EXR files from untrusted sources and avoid opening EXR files received from unknown parties. Linux distribution packages (Fedora, Red Hat, SUSE, etc.) have also issued updated packages addressing this CVE (Red Hat Bugzilla).
The vulnerability was discovered and disclosed by an anonymous researcher through Trend Micro's Zero Day Initiative (ZDI) program, with coordinated disclosure completed on 2025-11-11. Red Hat tracked the issue via Bugzilla and rated it high severity, with downstream Linux distributions including Fedora and SUSE issuing security updates. Splunk also issued an advisory (SVD-2026-0309) referencing this CVE, indicating the vulnerability's reach into enterprise software stacks that bundle OpenEXR (ZDI Advisory, Red Hat Bugzilla).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."