Out-of-Bounds Write Vulnerability in Ashlar-Vellum Cobalt Application
CVE-2023-39943

8.4HIGH

Key Information:

Vendor
CVE Published:
4 February 2025

What is CVE-2023-39943?

The Ashlar-Vellum Cobalt application suffers from an out-of-bounds write vulnerability due to insufficient validation of user-supplied data when parsing XE files. This flaw could enable an attacker to perform arbitrary code execution within the context of the current process, potentially compromising the system and exposing sensitive information.

Affected Version(s)

Argon 0

Cobalt 0

Cobalt Share 0

References

CVSS V4

Score:
8.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Michael Heinzl reported these vulnerabilities to CISA.
.