CVE-2025-7997

7.8

Ashlar-Vellum · Cobalt

A remote code execution vulnerability in Ashlar-Vellum Cobalt exists due to an out-of-bounds read flaw during the parsing of XE files.

Executive summary

A critical out-of-bounds read vulnerability in Ashlar-Vellum Cobalt allows remote attackers to execute arbitrary code via malicious file processing.

Vulnerability

The flaw resides in the XE file parsing logic, which fails to properly validate user-supplied data. This results in an out-of-bounds read that enables an unauthenticated attacker to execute arbitrary code, provided the user is tricked into opening a malicious file or visiting a compromised page.

Business impact

Successful exploitation of this vulnerability allows an attacker to achieve code execution in the context of the user process. Given the CVSS score of 7.8, this presents a significant risk to data integrity and system confidentiality. Organizations relying on this software face potential unauthorized access to sensitive design files and internal system compromises.

Remediation

Immediate Action: Since a specific patch version is not currently listed, administrators should contact Ashlar-Vellum support to verify the availability of an update for version 12 SP1.

Proactive Monitoring: Monitor file access logs and endpoint activity for unusual application behavior or unexpected process execution triggered by file parsing operations.

Compensating Controls: Advise users to exercise extreme caution when opening unsolicited or untrusted XE files, and ensure that endpoint protection solutions are configured to scan files upon access.

Exploitation status

Public Exploit Available: No (exploit_available: false).

Analyst recommendation

This vulnerability represents a serious threat to the integrity of workstations running Ashlar-Vellum Cobalt. Security teams should prioritize identifying all instances of the affected version and prepare to deploy the vendor-supplied fix as soon as it becomes available to prevent potential exploitation.

Sources