Out-Of-Bounds Write Vulnerability in Ashlar-Vellum Cobalt AR File Parsing
CVE-2024-13044

7.8HIGH

Key Information:

Status
Vendor
CVE Published:
30 December 2024

What is CVE-2024-13044?

The vulnerability allows remote attackers to exploit installations of Ashlar-Vellum Cobalt through the improper handling of data during the parsing of AR files. This exploitation requires user interaction, such as visiting a malicious webpage or opening a compromised file. The root cause of the issue lies in the insufficient validation of user-supplied data, which leads to a buffer overflow scenario. By manipulating this flaw, an attacker could execute arbitrary code in the context of the affected software process, highlighting the importance of robust security measures and user awareness.

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

.