Heap-Based Buffer Overflow in Ashlar-Vellum Applications
CVE-2025-46269

8.4HIGH

Key Information:

Vendor
CVE Published:
18 August 2025

What is CVE-2025-46269?

The Ashlar-Vellum software suite, including Cobalt, Xenon, Argon, Lithium, and Cobalt Share, is susceptible to a heap-based buffer overflow due to inadequate validation of user-supplied data when parsing VC6 files. This vulnerability could enable an attacker to execute arbitrary code within the context of the affected application, potentially compromising the integrity and confidentiality of the system.

Affected Version(s)

Argon 0 < 12.6.1204.204

Cobalt 0 < 12.6.1204.204

Cobalt Share 0 < 12.6.1204.204

References

CVSS V4

Score:
8.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Michael Heinzl reported these vulnerabilities to CISA.
.
CVE-2025-46269 : Heap-Based Buffer Overflow in Ashlar-Vellum Applications