CVE-2025-7994
7.8Ashlar-Vellum · Cobalt
A remote code execution vulnerability in Ashlar-Vellum Cobalt due to an out-of-bounds read during AR file parsing, requiring user interaction to trigger.
Executive summary
An out-of-bounds read vulnerability in Ashlar-Vellum Cobalt 12 SP1 allows remote attackers to execute arbitrary code on the host system via malicious AR files.
Vulnerability
This vulnerability is an out-of-bounds read flaw (CWE-125) occurring during the parsing of AR files. An unauthenticated attacker can achieve remote code execution by tricking a user into opening a specially crafted file.
Business impact
The vulnerability carries a CVSS score of 7.8, reflecting its high severity due to the potential for total system compromise. Successful exploitation grants an attacker the ability to execute arbitrary code in the context of the user, which could lead to full loss of confidentiality, integrity, and availability of the affected workstation or server.
Remediation
Immediate Action: Organizations should restrict the opening of untrusted AR files and consult the vendor for security patches or configuration updates.
Proactive Monitoring: Security teams should monitor for unusual application crashes or unexpected processes spawning from the Cobalt application.
Compensating Controls: Deploy endpoint protection software to scan files for malicious signatures and enforce the use of least privilege to limit the impact of potential code execution.
Exploitation status
Public Exploit Available: No confirmed public exploit (exploit_available: false).
Analyst recommendation
Given the critical impact of potential remote code execution, users of Ashlar-Vellum Cobalt 12 SP1 should prioritize security updates as they become available. Until a patch is applied, maintain high vigilance regarding the source of AR files and employ strict endpoint security policies to mitigate the risk of malicious file execution.