Remote Code Execution Vulnerability in Ashlar-Vellum Cobalt AR File Parsing
CVE-2025-7984

7.8HIGH

Key Information:

Status
Vendor
CVE Published:
17 September 2025

What is CVE-2025-7984?

This vulnerability arises from improper handling of AR file parsing in Ashlar-Vellum Cobalt. It allows remote attackers to execute arbitrary code on the affected installations. Exploitation requires the user to interact with a malicious page or open a harmful file, as the flaw stems from uninitialized memory being accessed during the parsing process. Attackers can leverage this vulnerability to execute code within the context of the current process, raising significant security concerns.

Affected Version(s)

Cobalt 1204.96

References

CVSS V3.0

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-7984 : Remote Code Execution Vulnerability in Ashlar-Vellum Cobalt AR File Parsing