CVE-2025-15467 | OpenSSL up to 3.0.18/3.3.5/3.4.3/3.5.4/3.6.0 AuthEnvelopedData Message out-of-bounds write (EUVD-2025-206379 / Nessus ID 296783)
A vulnerability classified as critical has been found in OpenSSL up to 3.0.18/3.3.5/3.4.3/3.5.4/3.6.0. This vulnerability affects unknown code of the component AuthEnvelopedData Message Handler. This manipulation causes out-of-bounds write.
This vulnerability is tracked as CVE-2025-15467. The attack is possible to be carried out remotely. No exploit exists.
It is recommended to upgrade the affected component.