Out-of-Bounds Read Vulnerability in Ashlar-Vellum Applications
CVE-2025-41392
8.4HIGH
What is CVE-2025-41392?
The Ashlar-Vellum applications Cobalt, Xenon, Argon, Lithium, and Cobalt Share contain a vulnerability due to insufficient validation of user-supplied data when parsing AR files. This flaw may result in an out-of-bounds read, allowing an attacker to exploit it for arbitrary code execution within the context of the current process. Users are advised to update to the latest versions to mitigate potential threats.
Affected Version(s)
Argon 0 < 12.6.1204.204
Cobalt 0 < 12.6.1204.204
Cobalt Share 0 < 12.6.1204.204
References
CVSS V4
Score:
8.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Michael Heinzl reported these vulnerabilities to CISA.