Remote Code Execution Vulnerability in Ashlar-Vellum Cobalt
CVE-2025-7990

7.8HIGH

Key Information:

Status
Vendor
CVE Published:
17 September 2025

What is CVE-2025-7990?

The vulnerability in Ashlar-Vellum Cobalt arises from improper validation during the parsing of VC6 files, enabling an attacker to perform an out-of-bounds write. This flaw allows remote execution of arbitrary code, necessitating user interaction, such as visiting a malicious site or opening a compromised file. The exploitation of this weakness can lead to significant security breaches, highlighting the importance of caution when handling VC6 files.

Affected Version(s)

Cobalt 12 SP1

References

CVSS V3.0

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-7990 : Remote Code Execution Vulnerability in Ashlar-Vellum Cobalt