CVE-2025-7996
7.8Ashlar-Vellum · Cobalt
Ashlar-Vellum Cobalt contains an out-of-bounds write vulnerability in its AR file parsing logic, which can be leveraged by a remote attacker to achieve arbitrary code execution.
Executive summary
A critical out-of-bounds write vulnerability in Ashlar-Vellum Cobalt 12 SP1 enables remote code execution if a user opens a malicious AR file.
Vulnerability
The vulnerability is an out-of-bounds write (CWE-787) flaw triggered during the parsing of AR files. It requires user interaction, specifically the opening of a malicious file or visiting a compromised page, to execute code within the context of the current process.
Business impact
The ability for an attacker to execute arbitrary code on a victim's workstation poses a significant risk to organizational data integrity and system confidentiality. With a CVSS score of 7.8, this high-severity vulnerability could lead to full system compromise if exploited successfully. The potential for lateral movement following initial execution makes this a priority for remediation, particularly for users handling untrusted CAD documents.
Remediation
Immediate Action: Since a specific patch is not yet confirmed, restrict the opening of untrusted AR files and monitor vendor communications for upcoming security updates.
Proactive Monitoring: Review endpoint security logs for unexpected process spawns originating from the Cobalt application.
Compensating Controls: Implement strict file type filtering and ensure that endpoint detection and response (EDR) solutions are configured to block suspicious document parsing activities.
Exploitation status
Public Exploit Available: No (exploit_available: false).
Analyst recommendation
Given the potential for complete system compromise, administrators should treat this vulnerability with high priority. Users should be advised to exercise caution when opening AR files from untrusted sources until the vendor provides a verified patch. Continuous monitoring of security advisories from Ashlar-Vellum is required to ensure the patch is applied immediately upon its release.