CVE-2025-7979
7.8Ashlar-Vellum · Graphite
A stack-based buffer overflow in Ashlar-Vellum Graphite allows remote code execution when parsing malicious VC6 files, requiring user interaction to trigger the vulnerability.
Executive summary
A critical stack-based buffer overflow vulnerability in Ashlar-Vellum Graphite permits remote code execution through the parsing of specially crafted files.
Vulnerability
The software fails to validate the length of user-supplied data during the parsing of VC6 files before copying it to a stack-based buffer. This vulnerability allows an unauthenticated attacker to achieve remote code execution if a user is coerced into opening a malicious file.
Business impact
The ability for an attacker to execute arbitrary code on a victim's workstation poses a severe risk of total system compromise, data theft, and lateral movement within the corporate network. With a CVSS score of 7.8, this flaw is categorized as High, reflecting the significant potential for impact despite the requirement for user interaction. Organizations relying on this software for engineering or design workflows face substantial operational disruption if these systems are compromised.
Remediation
Immediate Action: Contact the vendor or monitor the official Ashlar-Vellum support portal for the release of a security patch addressing the VC6 parsing flaw.
Proactive Monitoring: Review endpoint security logs for unexpected process execution or memory corruption errors associated with the Graphite application.
Compensating Controls: Implement strict file access policies and ensure that users are trained to avoid opening untrusted or unsolicited VC6 files from unknown sources.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Given the potential for remote code execution, this vulnerability represents a significant security risk to any environment utilizing Ashlar-Vellum Graphite. Administrators should prioritize identifying all instances of version 13_SE_13048 and prepare for immediate deployment of vendor-supplied updates as soon as they become available. Until a patch is released, users must exercise extreme caution regarding the source of files processed by the application.