CYBER CODE RED

Get real-time updates on Telegram

P4Verified

CVE-2025-59489: editor 2017.1.2p4+, 2017.2.0p4+, 2017.3.0b9+; +1 more affected products

CVE-2025-59489. CVSS 3.1 base score 7.4 (HIGH, Vendor/CNA). EPSS 0.00644 (percentile 0.49301), scored 2026-10-08.

Affected technology

editor · from 2017.4 (inclusive), through 2018.4 (inclusive)
unity

editor · from 2019.1 (inclusive), before 2019.1.15f1 (exclusive)
unity

editor · from 2019.2 (inclusive), before 2019.2.23f1 (exclusive)
unity

editor · from 2019.3 (inclusive), through 2019.3.17f1 (inclusive)
unity

editor · from 2019.4 (inclusive), before 2019.4.41f1 (exclusive)
unity

editor · from 2020.1 (inclusive), before 2020.1.18f1 (exclusive)
unity

editor · from 2020.2 (inclusive), before 2020.2.8f1 (exclusive)
unity

editor · from 2020.3 (inclusive), before 2020.3.49f1 (exclusive)
unity

editor · from 2021.1 (inclusive), before 2021.1.29f1 (exclusive)
unity

editor · from 2021.2 (inclusive), before 2021.2.20f1 (exclusive)
unity

editor · from 2021.3 (inclusive), before 2021.3.45f2 (exclusive)
unity

editor · from 2022.1 (inclusive), before 2022.1.25f1 (exclusive)
unity

editor · from 2022.2 (inclusive), before 2022.2.23f1 (exclusive)
unity

editor · from 2022.3 (inclusive), before 2022.3.62f2 (exclusive)
unity

editor · from 2023.1 (inclusive), before 2023.1.22f1 (exclusive)
unity

editor · from 2023.2 (inclusive), before 2023.2.22f1 (exclusive)
unity

editor · from 6000.0 (inclusive), before 6000.0.58f2 (exclusive)
unity

editor · from 6000.1 (inclusive), before 6000.1.17f1 (exclusive)
unity

editor · from 6000.2 (inclusive), before 6000.2.6f2 (exclusive)
unity

editor · from 6000.3 (inclusive), before 6000.3.0b4 (exclusive)
unity

editor · 2017.1.2p4+
unity

editor · 2017.2.0p4+
unity

editor · 2017.3.0b9+
unity

Unity Editor · 6000.3 to before 6000.3.0b4, 6000.2 to before 6000.2.6f2, 6000.0 LTS to before 6000.0.58f2, 2022.3 xLTS to before 2022.3.67f2, 2021.3 xLTS to before 2021.3.56f2, 6000.1 to before 6000.1.17f1, 2023.2 to before 2023.2.22f1, 2023.1 to before 2023.1.22f1, 2022.3 LTS to before 2022.3.62f2, 2022.2 to before 2022.2.23f1, 2022.1 to before 2022.1.25f1, 2021.3 LTS to before 2021.3.45f2, 2021.2 to before 2021.2.20f1, 2021.1 to before 2021.1.29f1, 2020.3 to before 2020.3.49f1, 2020.2 to before 2020.2.8f1, 2020.1 to before 2020.1.18f1, 2019.4 LTS to before 2019.4.41f1, 2019.3 to before 2019.3.17f1, 2019.2 to before 2019.2.23f1, 2017.1.2p4 to before 2019.1.15f1
Unity3D

Description’s affected range: before 2025-10-02 on Android, Windows, macOS, and Linux

Component: Not specified by the source

Attack conditions (Vendor/CNA, CVSS 3.1): Local · No privileges required · No user interaction required

Attack conditions (Source advisory, CVSS 3.1): Local · No privileges required · No user interaction required

What an attacker can do

Vendor/CNA’s CVSS 3.1 assessment (base score 7.4/10) rates confidentiality, integrity and availability impact as high. Source advisory’s CVSS 3.1 assessment (base score 8.4/10) rates confidentiality, integrity and availability impact as high. The description does not specify what an attacker can achieve beyond these rated impacts.

Published

CWE
CWE-88, CWE-426
CCR priority
29.8 /100 (P4)
CVSS 3.1
7.4 /10 · CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H · Vendor/CNA
EPSS
0.00644 · percentile 0.49301 · 2026-10-08
KEV
no

Provenance

Stable permalink: https://cybercodered.org/item/cve-cve-2025-59489.html