Out-of-Bounds Read Vulnerability in Ashlar-Vellum Products
CVE-2025-65088

8.4HIGH

Key Information:

Vendor
CVE Published:
12 May 2026

What is CVE-2025-65088?

An Out-of-Bounds Read vulnerability exists in Ashlar-Vellum products, specifically in versions 12.6.1204.216 and earlier. This flaw can be exploited when an attacker processes a specially crafted VC6 file, potentially leading to information disclosure or the execution of arbitrary code. This jeopardizes the integrity of user data and system security, making it crucial for affected users to promptly apply security updates.

Affected Version(s)

Argon 0 <= 12.6.1204.216

Cobalt 0 <= 12.6.1204.216

Cobalt Share 0 <= 12.6.1204.216

References

CVSS V4

Score:
8.4
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Michael Heinzl reported these vulnerabilities to CISA.
.