CVE-2025-7999

7.8

Ashlar-Vellum · Cobalt

A type confusion vulnerability in Ashlar-Vellum Cobalt allows remote code execution when a user opens a specially crafted AR file.

Executive summary

A type confusion vulnerability in Ashlar-Vellum Cobalt 12 SP1 enables remote code execution, posing a high risk to system integrity and confidentiality.

Vulnerability

The vulnerability is a type confusion flaw (CWE-843) occurring during the parsing of AR files. It requires the target user to interact with a malicious file or page to trigger the execution of arbitrary code in the context of the current process.

Business impact

Successful exploitation allows an attacker to execute arbitrary code with the privileges of the victim, potentially leading to a full system compromise. Given the CVSS score of 7.8, this vulnerability represents a significant risk, particularly if users frequently handle untrusted design files, as it could result in unauthorized data access or the installation of persistent malicious software.

Remediation

Immediate Action: Monitor official vendor communication channels for the release of a security patch and apply it immediately upon availability.

Proactive Monitoring: Review system access logs for anomalous behavior related to the parsing of AR files and implement endpoint detection to identify suspicious process execution chains.

Compensating Controls: Advise users to exercise caution when opening AR files from untrusted sources and employ robust endpoint security solutions to scan files for malicious indicators before they are opened.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Organizations utilizing Ashlar-Vellum Cobalt 12 SP1 should prioritize identifying affected workstations and restricting the handling of untrusted AR files. While no patch is currently identified, maintaining a high state of vigilance and preparing for rapid deployment of vendor updates is essential to mitigating the risk of remote code execution.

Sources