Type Confusion Vulnerability in Ashlar-Vellum Cobalt File Parsing
CVE-2025-7999

7.8HIGH

Key Information:

Status
Vendor
CVE Published:
17 September 2025

What is CVE-2025-7999?

The vulnerability in Ashlar-Vellum Cobalt's AR file parsing arises from insufficient validation of user-supplied data, leading to a type confusion condition. Attackers can exploit this flaw by enticing users to open a malicious file or visit a harmful webpage, allowing them to execute arbitrary code within the affected system. As a result, the security and integrity of the user’s environment could be compromised, making it imperative for users to follow best practices for file handling and software updates.

Affected Version(s)

Cobalt 12 SP1

References

CVSS V3.0

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-7999 : Type Confusion Vulnerability in Ashlar-Vellum Cobalt File Parsing