Remote Code Execution Vulnerability in Ashlar-Vellum Cobalt CO File Parsing
CVE-2024-13046

7.8HIGH

Key Information:

Status
Vendor
CVE Published:
30 December 2024

What is CVE-2024-13046?

A vulnerability exists within the parsing of CO files in Ashlar-Vellum Cobalt, allowing remote attackers to exploit erroneous handling of user-supplied data. This issue arises when insufficient validation of input leads to an out-of-bounds write, permitting execution of arbitrary code in the context of the host process. For successful exploitation, user interaction is necessary, requiring the target to either open a malicious file or visit a compromised web page. Understanding the implications of this vulnerability is critical for maintaining the security of systems utilizing Ashlar-Vellum Cobalt.

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

.