CVE-2025-7987

7.8

Ashlar-Vellum · Graphite

Ashlar-Vellum Graphite contains an out-of-bounds write vulnerability in VC6 file parsing, which allows a remote attacker to execute arbitrary code via a specially crafted file.

Executive summary

A critical out-of-bounds write vulnerability in Ashlar-Vellum Graphite version 13.0 enables remote code execution if a user opens a malicious file.

Vulnerability

This is an out-of-bounds write vulnerability (CWE-787) triggered during the parsing of VC6 files. An attacker can achieve remote code execution by tricking a user into opening a malicious file, as the software fails to properly validate user-supplied data during the parsing process.

Business impact

Successful exploitation allows an attacker to execute arbitrary code within the context of the current user session, which may lead to a complete system compromise. Given the CVSS score of 7.8, this vulnerability poses a significant risk to data confidentiality, integrity, and availability, particularly if the affected software is run by users with elevated system permissions.

Remediation

Immediate Action: Since no specific patch version is currently identified, users should exercise extreme caution when opening VC6 files from untrusted sources and monitor vendor communication channels for forthcoming security updates.

Proactive Monitoring: Security teams should monitor endpoint logs for suspicious process execution patterns originating from the Ashlar-Vellum application.

Compensating Controls: Deploy endpoint protection solutions capable of identifying and blocking malicious file execution or signature-based detection for known malicious file formats.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Organizations utilizing Ashlar-Vellum Graphite 13.0 must treat this vulnerability with high priority. Ensure that users are instructed to avoid opening untrusted VC6 files and verify that all software updates from Ashlar-Vellum are applied as soon as they become available to mitigate the risk of remote code execution.

Sources