CVE-2025-8000

7.8

Ashlar-Vellum · Cobalt

A type confusion vulnerability in Ashlar-Vellum Cobalt allows remote attackers to execute arbitrary code via malicious LI files, requiring user interaction to trigger the flaw.

Executive summary

A critical type confusion vulnerability in Ashlar-Vellum Cobalt 12 SP1 can lead to remote code execution when a user opens a specially crafted LI file.

Vulnerability

The software contains a type confusion flaw within its LI file parsing logic due to improper validation of user-supplied data. An unauthenticated attacker can exploit this by enticing a user to open a malicious file, leading to code execution in the context of the application process.

Business impact

The vulnerability poses a severe risk to organizational security by enabling remote code execution, which may result in full system compromise, data exfiltration, or the installation of persistent threats. Given the CVSS score of 7.8, this flaw is categorized as High severity and represents a significant risk to workstations or servers that process untrusted CAD files.

Remediation

Immediate Action: Since no specific patch version is currently identified, contact Ashlar-Vellum support to confirm the availability of an update or security fix for Cobalt 12 SP1.

Proactive Monitoring: Monitor endpoint activity for suspicious processes spawned by the Cobalt application and review file access logs for interactions with untrusted LI files.

Compensating Controls: Implement strict email filtering and endpoint protection policies to block or sandbox incoming LI files from unknown or untrusted external sources.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

Security teams should treat this vulnerability with high urgency, particularly in design or engineering departments where external files are frequently opened. Until a vendor-supplied patch is confirmed and applied, organizations must enforce strict user awareness training regarding the risks of opening unsolicited files and ensure that endpoint security solutions are configured to scan all incoming data for malicious patterns.

Sources