THREAT OPS › Threat News › [NVD] CVE-2025-15467 (HIGH 8.8) — Issue summary: Parsing CMS AuthEnvelopedData or EnvelopedData message with
maliciously crafted AEAD parameters can trigger a stack buffer overflow.
Impact summary: A stack buffer overflow may lead to a crash, causing Denial
of Service, or potentially remote code execution.
When
[NVD] CVE-2025-15467 (HIGH 8.8) — Issue summary: Parsing CMS AuthEnvelopedData or EnvelopedData message with maliciously crafted AEAD parameters can trigger a stack buffer overflow. Impact summary: A stack buffer overflow may lead to a crash, causing Denial of Service, or potentially remote code execution. When
CVE-2025-15467 CVSS: 8.8 HIGH Published: 2026-01-27T16:16:14.257
Issue summary: Parsing CMS AuthEnvelopedData or EnvelopedData message with maliciously crafted AEAD parameters can trigger a stack buffer overflow.
Impact summary: A stack buffer overflow may lead to a crash, causing Denial of Service, or potentially remote code execution.
When parsing CMS (Auth)EnvelopedData structures that use A
Indicators of compromise
- CVE-2025-15467cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2025-15467