Out-Of-Bounds Write Remote Code Execution in Ashlar-Vellum Graphite
CVE-2025-7987
7.8HIGH
What is CVE-2025-7987?
A vulnerability exists in Ashlar-Vellum Graphite's VC6 file parsing mechanism. Insufficient validation of user-provided data can lead to an out-of-bounds write, enabling remote attackers to execute arbitrary code on impacted systems. Exploitation requires user interaction, such as visiting a malicious webpage or opening a compromised file, allowing an attacker to run code within the context of the current process.
Affected Version(s)
Graphite 13.0