Out-Of-Bounds Write Vulnerability in Ashlar-Vellum Cobalt Product
CVE-2025-2020

7.8HIGH

Key Information:

Status
Vendor
CVE Published:
11 March 2025

What is CVE-2025-2020?

The vulnerability in Ashlar-Vellum Cobalt involves an out-of-bounds write that occurs during the parsing of VC6 files. Due to inadequate validation of user-supplied data, attackers may exploit this flaw to execute arbitrary code when a user engages with malicious content, such as visiting a compromised webpage or opening an infected file. This exploitation can occur within the context of the current process, posing significant risks to user environments.

Affected Version(s)

Cobalt 1204.91

References

CVSS V3.0

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.