
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-14935 is a heap-based buffer overflow vulnerability in NSF Unidata NetCDF-C that allows remote attackers to execute arbitrary code on affected installations. The flaw exists within the parsing of dimension names, where user-supplied data length is not validated before being copied into a fixed-length heap-based buffer. It was discovered by researcher Fady Othman, reported to the vendor on June 3, 2025, and publicly disclosed as a 0-day advisory on December 18, 2025, after the vendor failed to provide a patch. The CVE was formally published on December 23, 2025, and carries a CVSS v3.0 base score of 7.8 (High), assigned by the Zero Day Initiative (ZDI Advisory).
The root cause is classified as CWE-122 (Heap-based Buffer Overflow) and CWE-787 (Out-of-bounds Write), stemming from the absence of proper length validation when processing dimension name fields in NetCDF-C file parsing routines. An attacker crafts a malicious NetCDF file (or hosts it on a malicious page) containing an oversized dimension name string; when the library parses this file, the unchecked data is copied into a fixed-size heap buffer, causing an overflow that can overwrite adjacent heap memory. Exploitation requires user interaction — specifically, the target must open a malicious file or visit a page that triggers NetCDF-C parsing. The attack vector is local (the file must be processed on the victim's system), with no privileges required (ZDI Advisory, NVD).
Successful exploitation allows an attacker to execute arbitrary code in the context of the current user, resulting in high confidentiality, integrity, and availability impact. An attacker who achieves code execution could read sensitive data accessible to the user, modify or destroy files, and potentially crash the application. Because NetCDF-C is widely used in scientific computing, climate research, and data analysis pipelines, exploitation could affect research data integrity or serve as an entry point for further lateral movement within scientific computing environments (ZDI Advisory).
This vulnerability was published as a 0-day advisory by ZDI on December 18, 2025, meaning no vendor patch was available at the time of disclosure. No public proof-of-concept exploit code or in-the-wild exploitation has been reported as of the available data. The EPSS score is approximately 0.046% (0.000460), indicating a low current probability of exploitation in the wild. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The ZDI advisory (ZDI-25-1154) serves as the primary public reference (ZDI Advisory).
.nc (NetCDF) files in user download directories, temporary folders, or email attachments with unusually large dimension name fields./bin/sh, cmd.exe) or network utilities (curl, wget).No vendor patch has been released as of the disclosure date; ZDI published this as a 0-day after the vendor did not respond with a fix within the coordinated disclosure window. The only recommended mitigation from ZDI is to restrict interaction with the NetCDF-C product — specifically, avoid opening NetCDF files from untrusted sources. Organizations should implement file-type filtering and user awareness to prevent processing of untrusted .nc files. Monitor the NSF Unidata GitHub repository and official channels for patch releases and apply them promptly when available (ZDI Advisory).
The vulnerability was credited to researcher Fady Othman and disclosed by the Zero Day Initiative after an extended coordinated disclosure period during which the vendor acknowledged receipt but did not provide a patch or timeline. ZDI followed its standard policy of publishing after 180+ days without vendor remediation. No significant public commentary from the broader security community or media coverage beyond the ZDI advisory and vulnerability database entries has been identified (ZDI Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."