Remote Code Execution Vulnerability in Ashlar-Vellum Cobalt AR File Parsing
CVE-2025-7994

7.8HIGH

Key Information:

Status
Vendor
CVE Published:
17 September 2025

What is CVE-2025-7994?

An Out-Of-Bounds Read vulnerability exists in Ashlar-Vellum Cobalt due to inadequate validation of user-supplied data during AR file parsing. This flaw can be exploited by remote attackers to execute arbitrary code by convincing a user to visit a malicious webpage or open a specially crafted file. The attack results in unauthorized access within the context of the current process, potentially leading to severe security breaches.

Affected Version(s)

Cobalt 12 SP1

References

CVSS V3.0

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-7994 : Remote Code Execution Vulnerability in Ashlar-Vellum Cobalt AR File Parsing