Stack-based Buffer Overflow in Ashlar-Vellum Graphite VC6 File Parsing
CVE-2025-7979

7.8HIGH

Key Information:

Status
Vendor
CVE Published:
17 September 2025

What is CVE-2025-7979?

The vulnerability allows remote attackers to execute arbitrary code on Ashlar-Vellum Graphite installations through a stack-based buffer overflow resulting from poor validation of data input when processing VC6 files. This flaw requires user interaction, as the target must open a malicious VC6 file or visit a harmful webpage to trigger the exploit. By bypassing the system's protections, an attacker can gain control over the affected system, leading to potential data breaches or system compromise.

Affected Version(s)

Graphite 13_SE_13048

References

CVSS V3.0

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-7979 : Stack-based Buffer Overflow in Ashlar-Vellum Graphite VC6 File Parsing