CVE-2025-7982

7.8

Ashlar-Vellum · Cobalt

A remote code execution vulnerability in Ashlar-Vellum Cobalt exists due to an integer overflow during the parsing of LI files, which can be triggered by a user opening a malicious file.

Executive summary

A critical integer overflow vulnerability in Ashlar-Vellum Cobalt version 1204.96 allows remote attackers to execute arbitrary code via malicious LI file parsing.

Vulnerability

The vulnerability is an integer overflow (CWE-190) triggered during the parsing of LI files. An attacker can exploit this by enticing a user to open a specially crafted file, leading to arbitrary code execution in the context of the application process.

Business impact

The ability for an unauthenticated attacker to achieve remote code execution poses a severe risk to organizational data integrity and system availability. With a CVSS score of 7.8, this flaw could lead to a full compromise of the local system, unauthorized data access, or the deployment of persistent threats, resulting in significant operational disruption.

Remediation

Immediate Action: Contact the vendor immediately to obtain the latest security patches for Ashlar-Vellum Cobalt, as no official patch status is currently confirmed in public records.

Proactive Monitoring: Monitor system logs for unusual file-handling activity or unexpected process execution patterns within the Cobalt environment.

Compensating Controls: Restrict the opening of untrusted or externally sourced LI files and ensure that users operate with the least privilege necessary to perform their tasks.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the potential for remote code execution, organizations utilizing Ashlar-Vellum Cobalt version 1204.96 must prioritize this issue in their vulnerability management cycle. Administrators should monitor vendor communication channels closely for the release of an official update and apply it immediately to prevent exploitation of this integer overflow flaw.

Sources