CVE-2025-8845
HIGHCVSS 7.8/10EPSS 0.25%
Last modified
CVE-2025-8845 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. A vulnerability was identified in NASM Netwide Assember 2.17rc0. This issue affects the function assemble_file of the file nasm.c. EPSS estimates a 0.25% chance of exploitation in the next 30 days.
Description
A vulnerability was identified in NASM Netwide Assember 2.17rc0. This issue affects the function assemble_file of the file nasm.c. The manipulation leads to stack-based buffer overflow. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Nasm | Netwide Assembler | 2.17 | Rc0 |
References
- https://bugzilla.nasm.us/show_bug.cgi?id=3392937Exploit, Issue Tracking, Vendor Advisory
- https://vuldb.com/?ctiid.319379Permissions Required, VDB Entry
- https://vuldb.com/?id.319379Third Party Advisory, VDB Entry
- https://vuldb.com/?submit.623188Exploit, Third Party Advisory, VDB Entry
- https://bugzilla.nasm.us/show_bug.cgi?id=3392937Exploit, Issue Tracking, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-8845?
A vulnerability was identified in NASM Netwide Assember 2.17rc0. This issue affects the function assemble_file of the file nasm.c. The manipulation leads to stack-based buffer overflow. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used.
How severe is CVE-2025-8845?
CVE-2025-8845 has a CVSS score of 7.8/10 (HIGH severity). The EPSS model estimates a 0.25% probability of exploitation in the next 30 days.
How do I fix CVE-2025-8845?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-8839A vulnerability was found in jshERP up to 3.5. This issue af…8.8
- CVE-2025-8840A vulnerability was determined in jshERP up to 3.5. Affected…5.4
- CVE-2025-8841A vulnerability was identified in zlt2000 microservices-plat…6.1
- CVE-2025-8842A vulnerability has been found in NASM Netwide Assember 2.17…7.8
- CVE-2025-8843A vulnerability was found in NASM Netwide Assember 2.17rc0. …7.8
- CVE-2025-8844A vulnerability was determined in NASM Netwide Assember 2.17…5.5
- CVE-2025-8846A vulnerability has been found in NASM Netwide Assember 2.17…7.8
- CVE-2025-8847A vulnerability was found in yangzongzhuan RuoYi up to 4.8.1…5.4
- CVE-2025-8848A vulnerability in danny-avila/librechat version 0.7.9 allow…5.4
- CVE-2025-8849LibreChat version 0.7.9 is vulnerable to a Denial of Service…7.5
- CVE-2025-8850In danny-avila/librechat version 0.7.9, there is an insecure…8.8
- CVE-2025-8851A vulnerability was determined in LibTIFF up to 4.5.1. Affec…5.3
Are you affected by CVE-2025-8845?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
