Remote Code Execution Vulnerability in Ashlar-Vellum Graphite
CVE-2025-7981

7.8HIGH

Key Information:

Status
Vendor
CVE Published:
17 September 2025

What is CVE-2025-7981?

A vulnerability exists in Ashlar-Vellum Graphite due to improper initialization of variables when parsing VC6 files. This flaw allows remote attackers to potentially execute arbitrary code on vulnerable installations. To exploit this vulnerability, an attacker must induce the target user to interact with a malicious webpage or open a compromised file. A successful exploit could enable the attacker to execute code within the context of the susceptible process, posing significant security risks. For more details, refer to the advisory ZDI-25-634.

Affected Version(s)

Graphite 13_SE_13048

References

CVSS V3.0

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-7981 : Remote Code Execution Vulnerability in Ashlar-Vellum Graphite