CVE-2025-7980
7.8Ashlar-Vellum · Graphite
A critical out-of-bounds write vulnerability in Ashlar-Vellum Graphite allows remote code execution when a user opens a specially crafted VC6 file.
Executive summary
An out-of-bounds write vulnerability in Ashlar-Vellum Graphite poses a critical risk of remote code execution if a user is tricked into opening a malicious VC6 file.
Vulnerability
This vulnerability is an out-of-bounds write (CWE-787) occurring during the parsing of VC6 files, which lack sufficient validation of user-supplied data. An attacker can achieve remote code execution in the context of the current process, provided the victim is induced to open a malicious file.
Business impact
Successful exploitation of this flaw allows an attacker to execute arbitrary code on the victim's machine, potentially leading to a full system compromise, unauthorized data access, or the deployment of malware. With a CVSS score of 7.8, this vulnerability represents a high-severity risk to business operations, as it directly impacts the confidentiality, integrity, and availability of sensitive design assets and system environments.
Remediation
Immediate Action: Contact Ashlar-Vellum support to obtain the necessary security updates or configuration changes to address this flaw, as a public patch version is not currently identified.
Proactive Monitoring: Monitor system logs for unusual application crashes or file access patterns that deviate from standard operational behavior when opening VC6 files.
Compensating Controls: Advise users to exercise extreme caution when opening VC6 files from untrusted or unknown sources, and ensure that endpoint protection software is updated to detect malicious file signatures.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the potential for remote code execution, this vulnerability should be treated with high urgency within environments that utilize Ashlar-Vellum Graphite. Administrators should prioritize identifying affected installations and coordinating with the vendor to secure the environment against the risk of malicious file parsing.