CVE-2025-11465
7.8Ashlar-Vellum · Cobalt
A use-after-free vulnerability exists in Ashlar-Vellum Cobalt during the parsing of CO files, which allows remote attackers to execute arbitrary code via a malicious file.
Executive summary
A critical use-after-free vulnerability in Ashlar-Vellum Cobalt allows for remote code execution when a user opens a specially crafted file.
Vulnerability
The flaw exists within the parsing of CO files due to a failure to validate object existence before performing operations. This use-after-free vulnerability requires user interaction, such as opening a malicious file, and can be triggered by an unauthenticated attacker to execute code in the context of the current process.
Business impact
The ability for an attacker to achieve remote code execution poses a severe risk to organizational security. Successful exploitation could lead to full system compromise, unauthorized access to proprietary design data, and potential lateral movement within the network. With a CVSS score of 7.8, this vulnerability represents a high-severity threat that requires immediate attention to prevent significant operational and data integrity impacts.
Remediation
Immediate Action: Since a specific patch is not currently confirmed, users should avoid opening untrusted or unsolicited CO files until an official update is released by Ashlar-Vellum.
Proactive Monitoring: Security teams should monitor workstation endpoints for unusual process spawning or unexpected crashes of the Cobalt application, which may indicate exploitation attempts.
Compensating Controls: Deploy endpoint detection and response (EDR) solutions to identify and block malicious activity originating from the Cobalt process, and utilize file integrity monitoring for critical directories.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Given the potential for remote code execution, this vulnerability should be treated as a high priority. Administrators should monitor vendor communication channels closely for the release of an official security update and apply it immediately upon availability. In the interim, enforce strict file handling policies to minimize the risk of users interacting with malicious CO files.