Type Confusion Remote Code Execution Vulnerability in Ashlar-Vellum Cobalt
CVE-2025-8000
7.8HIGH
What is CVE-2025-8000?
A vulnerability in the Ashlar-Vellum Cobalt LI file parsing can allow remote attackers to execute arbitrary code. This issue arises due to insufficient validation of user-supplied data, leading to a type confusion scenario. Exploitation requires user interaction, as victims must access a malicious webpage or open a harmful file. Successful exploitation can enable attackers to execute code within the context of the affected process, posing significant security risks.
Affected Version(s)
Cobalt 12 SP1