Out-Of-Bounds Write Vulnerability in Ashlar-Vellum Graphite
CVE-2025-7986
7.8HIGH
What is CVE-2025-7986?
The Out-Of-Bounds Write vulnerability in Ashlar-Vellum Graphite arises from improper validation of user input during the parsing of VC6 files. This flaw permits an attacker to execute arbitrary code remotely by manipulating data sent to the application. Exploitation requires user interaction, as victims must either access a malicious website or open a compromised VC6 file. When the application fails to adequately check for buffer limits, it results in a write operation that exceeds allocated memory space. This allows attackers to execute code within the context of the vulnerable process, potentially leading to significant security compromises.
Affected Version(s)
Graphite 13.0