CVE-2025-7992

7.8

Ashlar-Vellum · Cobalt

A critical out-of-bounds read vulnerability in Ashlar-Vellum Cobalt allows remote code execution when a user opens a specially crafted AR file.

Executive summary

A critical out-of-bounds read vulnerability in Ashlar-Vellum Cobalt version 12 SP1 enables remote code execution through malicious file parsing, posing a significant risk to system integrity.

Vulnerability

This vulnerability is an out-of-bounds read flaw (CWE-125) occurring during the parsing of AR files. An unauthenticated attacker can trigger this issue if a user opens a malicious file, leading to arbitrary code execution within the context of the application.

Business impact

The ability to execute arbitrary code grants an attacker full control over the affected system, potentially leading to unauthorized data access, persistence, or lateral movement within the network. With a CVSS score of 7.8, the vulnerability is classified as High severity, reflecting the significant potential for system compromise despite the requirement for user interaction.

Remediation

Immediate Action: Since a specific patch version is currently unconfirmed, users should restrict the opening of untrusted AR files and monitor vendor channels for the release of an official security update.

Proactive Monitoring: Security teams should monitor endpoint activity for unexpected child processes spawned by the Ashlar-Vellum Cobalt application.

Compensating Controls: Organizations should employ endpoint protection software configured to scan incoming files and block potentially malicious file formats before they reach the end user.

Exploitation status

Public Exploit Available: No (exploit_available: false).

Analyst recommendation

Given the severity of potential remote code execution, administrators must treat this vulnerability with high priority. While awaiting a formal vendor patch, ensure that users are educated on the risks of opening untrusted files and maintain robust endpoint monitoring to detect any anomalous behavior associated with the Cobalt software.

Sources