CVE-2025-7985

7.8

Ashlar-Vellum · Cobalt

A critical integer overflow vulnerability in Ashlar-Vellum Cobalt allows remote code execution via malicious VC6 file parsing.

Executive summary

An integer overflow vulnerability in Ashlar-Vellum Cobalt 1204.96 could allow an attacker to execute arbitrary code on the host system.

Vulnerability

The flaw exists in the VC6 file parsing logic, where insufficient validation of user-supplied data leads to an integer overflow during buffer allocation. This allows an unauthenticated attacker to execute arbitrary code in the context of the current process, provided the user is coerced into opening a malicious file.

Business impact

The ability for an attacker to execute arbitrary code poses a significant risk to data integrity, confidentiality, and system availability. With a CVSS score of 7.8, this vulnerability is categorized as High severity, as it facilitates full system compromise if successfully triggered. Such an event could lead to unauthorized access to sensitive intellectual property or the deployment of persistent malware within the corporate environment.

Remediation

Immediate Action: Update Ashlar-Vellum Cobalt to the latest version provided by the vendor to resolve the underlying integer overflow flaw.

Proactive Monitoring: Monitor system logs for unexpected application crashes or execution of child processes spawned by the Cobalt software, which may indicate an exploitation attempt.

Compensating Controls: Restrict the opening of untrusted VC6 files from unknown sources and ensure that endpoint protection solutions are configured to scan files for malicious patterns before they are processed by the application.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

Given the severity of potential remote code execution, organizations utilizing Ashlar-Vellum Cobalt should prioritize the application of vendor-supplied patches. Users must be advised to exercise caution when handling VC6 files from external or untrusted sources until the software has been updated to a secure version.

Sources