Out-Of-Bounds Write Vulnerability in Ashlar-Vellum Cobalt Product
CVE-2025-2020
7.8HIGH
What is CVE-2025-2020?
The vulnerability in Ashlar-Vellum Cobalt involves an out-of-bounds write that occurs during the parsing of VC6 files. Due to inadequate validation of user-supplied data, attackers may exploit this flaw to execute arbitrary code when a user engages with malicious content, such as visiting a compromised webpage or opening an infected file. This exploitation can occur within the context of the current process, posing significant risks to user environments.
Affected Version(s)
Cobalt 1204.91