CVE-2025-7990
7.8Ashlar-Vellum · Cobalt
A critical out-of-bounds write vulnerability in Ashlar-Vellum Cobalt allows remote code execution when a user opens a specially crafted VC6 file.
Executive summary
A critical out-of-bounds write vulnerability in Ashlar-Vellum Cobalt version 12 SP1 enables remote code execution, posing a significant risk to system integrity and data confidentiality.
Vulnerability
This vulnerability is an out-of-bounds write flaw caused by insufficient validation of user-supplied data during the parsing of VC6 files. An unauthenticated attacker can trigger this vulnerability if a user is coerced into opening a malicious file, allowing the execution of arbitrary code in the context of the current process.
Business impact
The ability for an attacker to achieve remote code execution represents a total compromise of the affected host. Given the CVSS score of 7.8, this vulnerability carries a high severity, potentially leading to unauthorized data access, the installation of malware, or complete system takeover if the software is running with elevated permissions.
Remediation
Immediate Action: Users should exercise caution when opening untrusted VC6 files from unknown sources until an official vendor patch is released.
Proactive Monitoring: Monitor endpoint processes for unusual file system activity or unexpected child processes spawned by the Cobalt application.
Compensating Controls: Deploy endpoint detection and response solutions to identify and block suspicious file parsing behaviors or memory-based attacks associated with out-of-bounds write attempts.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
This vulnerability presents a serious risk to users of Ashlar-Vellum Cobalt 12 SP1 due to the potential for remote code execution. Administrators should restrict the opening of files from untrusted sources and monitor official vendor channels for the release of a security update. Applying the patch as soon as it becomes available is essential to remediate the underlying memory corruption flaw and protect the environment.