CVE-2025-66379
7.5Pexip · Infinity
Pexip Infinity versions prior to 39.0 contain a vulnerability involving improper input validation that can be triggered by a remote attacker to cause a denial of service.
Executive summary
A critical vulnerability in Pexip Infinity allows unauthenticated remote attackers to trigger a service crash, leading to potential denial of service.
Vulnerability
The software suffers from improper input validation within its media implementation, which is susceptible to a reachable assertion (CWE-617). An unauthenticated attacker can exploit this by sending a specially crafted media stream to the target, resulting in a software abort.
Business impact
The exploitation of this vulnerability results in a denial of service, which can disrupt critical communication and conferencing services managed by Pexip Infinity. Given the CVSS score of 7.5, this represents a high severity risk that could lead to significant operational downtime for organizations relying on the platform for real-time collaboration.
Remediation
Immediate Action: Upgrade Pexip Infinity to version 39.0 or later as specified in the official vendor security documentation.
Proactive Monitoring: Monitor system logs for repeated service crashes or unexpected restarts that could indicate an attempt to trigger this assertion.
Compensating Controls: Ensure that network perimeter defenses are configured to inspect incoming media traffic and block malformed or suspicious streams directed at the Pexip infrastructure.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Organizations should prioritize the update to Pexip Infinity version 39.0 to eliminate the vulnerability. Because the attack vector is remote and requires no authentication, the potential for automated exploitation is present, making timely remediation essential for maintaining system availability.