Remote Code Execution Vulnerability in Ashlar-Vellum Cobalt
CVE-2025-7990
7.8HIGH
What is CVE-2025-7990?
The vulnerability in Ashlar-Vellum Cobalt arises from improper validation during the parsing of VC6 files, enabling an attacker to perform an out-of-bounds write. This flaw allows remote execution of arbitrary code, necessitating user interaction, such as visiting a malicious site or opening a compromised file. The exploitation of this weakness can lead to significant security breaches, highlighting the importance of caution when handling VC6 files.
Affected Version(s)
Cobalt 12 SP1