CVE-2025-7991

7.8

Ashlar-Vellum · Cobalt

Ashlar-Vellum Cobalt contains an out-of-bounds read vulnerability in VC6 file parsing, which allows remote attackers to execute arbitrary code via malicious file interaction.

Executive summary

A critical out-of-bounds read vulnerability in Ashlar-Vellum Cobalt enables remote code execution when a user opens a specially crafted VC6 file.

Vulnerability

This flaw exists within the VC6 file parsing mechanism, where improper validation of user-supplied data leads to a read past the end of an allocated data structure. The vulnerability requires user interaction, as the target must open a malicious file or visit a malicious page to trigger the execution of arbitrary code in the context of the current process.

Business impact

Successful exploitation of this vulnerability allows an attacker to achieve remote code execution, granting them the ability to compromise the integrity, availability, and confidentiality of the host system. Given the CVSS score of 7.8, this represents a high-severity risk that could lead to unauthorized system access or data loss. Organizations relying on Cobalt for design workflows face significant operational disruption if their engineering workstations are compromised by malicious design files.

Remediation

Immediate Action: Contact Ashlar-Vellum support to obtain the latest security patches or guidance for mitigating the VC6 file parsing vulnerability, as a public patch version is not currently specified.

Proactive Monitoring: Monitor endpoint activity for suspicious processes spawned by the Cobalt application and review system logs for anomalous file access patterns.

Compensating Controls: Implement strict file-handling policies that restrict the opening of untrusted or externally sourced VC6 files in Cobalt until a vendor-supplied patch is applied.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

The potential for remote code execution via file parsing makes this a high-priority security concern. Administrators should immediately evaluate their exposure to external VC6 files and ensure that users are warned against opening files from untrusted sources while awaiting a formal vendor patch.

Sources