
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-14933 is an integer overflow remote code execution vulnerability in NSF Unidata NetCDF-C affecting NC variable parsing. Discovered by researcher Fady Osman and reported to the vendor on June 3, 2025, it was published as a zero-day advisory on December 18, 2025, after the vendor failed to release a patch within the disclosure window. The affected product is NSF Unidata NetCDF-C (all versions per available CPE data). It carries a CVSS v3.0 score of 7.8 (High), assigned by Zero Day Initiative (ZDI Advisory).
The vulnerability is classified as CWE-190 (Integer Overflow or Wraparound) and exists within the NC variable parsing logic of the NetCDF-C library. When processing user-supplied data in a malicious NetCDF file, the library fails to properly validate integer values before using them to calculate buffer allocation sizes, resulting in an integer overflow that leads to an undersized heap buffer allocation. An attacker can craft a malicious .nc file or host it on a web page to trigger the flaw when a victim opens the file or visits the page, ultimately achieving arbitrary code execution in the context of the current user (ZDI Advisory).
Successful exploitation grants an attacker arbitrary code execution in the context of the victim user, resulting in high confidentiality, integrity, and availability impact. An attacker could read sensitive data accessible to the user, modify or destroy files, or cause application crashes. Because NetCDF-C is widely used in scientific computing, climate research, and data analysis workflows, exploitation could affect research environments, data pipelines, and systems that automatically process NetCDF files (ZDI Advisory).
This vulnerability was published as a zero-day advisory on December 18, 2025, meaning no vendor patch was available at the time of public disclosure. The ZDI advisory serves as the primary exploit reference, though no public proof-of-concept code has been separately released. Exploitation requires user interaction (opening a malicious file or visiting a malicious page), which limits opportunistic mass exploitation but remains viable in targeted attacks via phishing or malicious file distribution. The EPSS score is approximately 0.046% (low), and the vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities catalog. No in-the-wild exploitation or threat actor attribution has been reported (ZDI Advisory).
.nc (NetCDF) file containing NC variable definitions with integer values designed to trigger an overflow when the library calculates buffer allocation sizes during parsing.ncdump)..nc files in download directories, temporary folders, or shared data locations; newly created or modified executables or scripts in user-writable directories following NetCDF file processing.ncdump, scientific analysis tools) such as shells (/bin/sh, cmd.exe), network utilities (curl, wget), or scripting interpreters.As of the advisory publication date (December 18, 2025), no vendor patch has been released by NSF Unidata, making this a zero-day vulnerability. ZDI's recommended mitigation is to restrict interaction with the NetCDF-C library and avoid opening untrusted or unknown NetCDF files. Organizations should implement strict file allowlisting, disable automatic processing of NetCDF files from untrusted sources, and monitor for anomalous process behavior in environments using NetCDF-C. Users should check the NSF Unidata GitHub repository for any patch releases and apply them promptly when available (ZDI Advisory).
The vulnerability was noted in automated vulnerability tracking feeds including VulDB and CIRCL's vulnerability lookup service shortly after the ZDI advisory was published. No significant public researcher commentary, vendor statements from NSF Unidata, or major media coverage has been identified beyond the ZDI advisory itself. The disclosure timeline reflects a protracted vendor engagement period of over six months with no patch produced, which prompted ZDI to publish the advisory as a zero-day (ZDI Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."