Out-of-Bounds Read Vulnerability in Ashlar-Vellum Applications
CVE-2025-41392

8.4HIGH

Key Information:

Vendor
CVE Published:
18 August 2025

What is CVE-2025-41392?

The Ashlar-Vellum applications Cobalt, Xenon, Argon, Lithium, and Cobalt Share contain a vulnerability due to insufficient validation of user-supplied data when parsing AR files. This flaw may result in an out-of-bounds read, allowing an attacker to exploit it for arbitrary code execution within the context of the current process. Users are advised to update to the latest versions to mitigate potential threats.

Affected Version(s)

Argon 0 < 12.6.1204.204

Cobalt 0 < 12.6.1204.204

Cobalt Share 0 < 12.6.1204.204

References

CVSS V4

Score:
8.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Michael Heinzl reported these vulnerabilities to CISA.
.
CVE-2025-41392 : Out-of-Bounds Read Vulnerability in Ashlar-Vellum Applications