Type Confusion in Ashlar-Vellum Cobalt VS File Parsing
CVE-2025-2018

7.8HIGH

Key Information:

Status
Vendor
CVE Published:
11 March 2025

What is CVE-2025-2018?

A type confusion vulnerability exists in the file parsing mechanism of Ashlar-Vellum Cobalt for VS files. This flaw allows remote attackers to execute arbitrary code by convincing a user to visit a malicious webpage or open a compromised file. The vulnerability arises due to insufficient validation of user-supplied data, leading to unintended consequences in code execution within the context of the current process. To mitigate risk, users should exercise caution when handling VS files and ensure they are sourced from trusted locations.

Affected Version(s)

Cobalt 1204.91

References

CVSS V3.0

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-2018 : Type Confusion in Ashlar-Vellum Cobalt VS File Parsing