Use-After-Free Vulnerability in Ashlar-Vellum Cobalt File Parsing
CVE-2025-11465

7.8HIGH

Key Information:

Status
Vendor
CVE Published:
29 October 2025

What is CVE-2025-11465?

The vulnerability in Ashlar-Vellum Cobalt arises during the parsing of CO files, where the application fails to properly validate the existence of an object before performing operations on it. This lack of validation could allow an attacker to execute arbitrary code on vulnerable systems, contingent upon the user interacting with a malicious page or file. Being aware of this vulnerability is crucial for maintaining the security of installations.

Affected Version(s)

Cobalt 1204.97

References

CVSS V3.0

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-11465 : Use-After-Free Vulnerability in Ashlar-Vellum Cobalt File Parsing