Out-of-Bounds Read Vulnerability in Ashlar-Vellum Products
CVE-2025-65088
8.4HIGH
What is CVE-2025-65088?
An Out-of-Bounds Read vulnerability exists in Ashlar-Vellum products, specifically in versions 12.6.1204.216 and earlier. This flaw can be exploited when an attacker processes a specially crafted VC6 file, potentially leading to information disclosure or the execution of arbitrary code. This jeopardizes the integrity of user data and system security, making it crucial for affected users to promptly apply security updates.
Affected Version(s)
Argon 0 <= 12.6.1204.216
Cobalt 0 <= 12.6.1204.216
Cobalt Share 0 <= 12.6.1204.216
References
CVSS V4
Score:
8.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Michael Heinzl reported these vulnerabilities to CISA.
