CVE-2025-7977

7.8

Ashlar-Vellum · Cobalt

A remote code execution vulnerability exists in Ashlar-Vellum Cobalt due to an out-of-bounds read error during the parsing of LI files, which can be triggered by processing a malicious file.

Executive summary

An out-of-bounds read vulnerability in Ashlar-Vellum Cobalt allows a remote attacker to execute arbitrary code on the host system if a user opens a specially crafted LI file.

Vulnerability

The vulnerability is an out-of-bounds read flaw (CWE-125) occurring during the parsing of LI files. It requires user interaction, specifically the opening of a malicious file, and allows an attacker to execute code in the context of the current user process.

Business impact

The ability for an attacker to execute arbitrary code poses a severe risk to organizational data and system integrity. Successful exploitation could lead to full system compromise, unauthorized access to sensitive intellectual property, or the installation of persistent malware. Given the CVSS score of 7.8, this flaw represents a high risk to business operations, particularly in environments where CAD software is used to process untrusted external files.

Remediation

Immediate Action: Since no specific patch version is currently identified, users should restrict the opening of LI files from untrusted or unknown sources until the vendor provides a security update.

Proactive Monitoring: Security teams should monitor system processes for anomalous activity or unexpected child processes spawned by the Cobalt application.

Compensating Controls: Deploy endpoint detection and response solutions to identify and block suspicious file execution patterns associated with CAD software parsing engines.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

Organizations utilizing Ashlar-Vellum Cobalt must exercise extreme caution when handling LI files from external entities. While a formal patch is pending, administrators should communicate the risk to end users and implement strict file handling policies to prevent the execution of malicious content. Monitor the vendor advisory portal frequently for the release of a corrective update.

Sources