Search/CVE-2025-54065
CVE — High

CVE-2025-54065

GZDoom is a feature centric port for all Doom engine games. GZDoom is an open source Doom engine. In versions 4.14.2 and earlier, ZScript actor state handling allows scripts to read arbitrary addresses, write constants into the JIT-compiled code section, and redirect control flow through crafted FState and VMFunction structures. A script can copy FState structures into a writable buffer, modify function pointers and state transitions, and cause execution of attacker-controlled bytecode, leading to arbitrary code execution.

CVSS v3.1
7.9 HIGH
EPSS
0.14%
probability of exploitation in 30 days
CISA KEV
Not listed
no confirmed exploitation reported
News coverage
0
sources referencing this CVE
EPSS Trend
Aug 16, 2026Aug 30, 2026
0.00pp
0.13% → 0.14% over 2 tracked changes
CVSS v3.1 Detail
Attack VectorLOCAL
Attack ComplexityLOW
Privileges RequiredLOW
User InteractionREQUIRED
ScopeCHANGED
ConfidentialityHIGH
IntegrityHIGH
AvailabilityNONE
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N
Connections
1 relationships
Timeline
disclosure → media coverage
Dec 3, 2025
Disclosure — published as a CVE record. · last revised by NVD Apr 15, 2026