THREATOPS
THREAT OPSThreat News › [NVD] CVE-2025-15467 (HIGH 8.8) — Issue summary: Parsing CMS AuthEnvelopedData or EnvelopedData message with maliciously crafted AEAD parameters can trigger a stack buffer overflow. Impact summary: A stack buffer overflow may lead to a crash, causing Denial of Service, or potentially remote code execution. When

[NVD] CVE-2025-15467 (HIGH 8.8) — Issue summary: Parsing CMS AuthEnvelopedData or EnvelopedData message with maliciously crafted AEAD parameters can trigger a stack buffer overflow. Impact summary: A stack buffer overflow may lead to a crash, causing Denial of Service, or potentially remote code execution. When

lownvdPublished 2026-01-27

CVE-2025-15467 CVSS: 8.8 HIGH Published: 2026-01-27T16:16:14.257

Issue summary: Parsing CMS AuthEnvelopedData or EnvelopedData message with maliciously crafted AEAD parameters can trigger a stack buffer overflow.

Impact summary: A stack buffer overflow may lead to a crash, causing Denial of Service, or potentially remote code execution.

When parsing CMS (Auth)EnvelopedData structures that use A

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2025-15467