Ashlar-Vellum Products Out-of-Bounds Read Vulnerability Allowing Arbitrary Code Execution

Vulnerability

A vulnerability exists in Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share, all versions prior to 12.6.1204.204. The issue arises from improper validation of user-supplied data when parsing AR files, leading to an out-of-bounds read. This vulnerability could be exploited by an attacker to execute arbitrary code within the context of the current process.

Impact

Exploitation of this vulnerability could result in an out-of-bounds read, potentially allowing an attacker to execute arbitrary code in the context of the current process.

Remediation

Users are advised to update to version 12.6.1204.204 or later. Ashlar-Vellum recommends checking for updates through the application's main menu. Additionally, users should only open supported file formats from trusted sources.

Added: Aug 18, 2025, 9:18 PM
Updated: Aug 18, 2025, 9:18 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
4.4
remediation
8.3
relevance
0.3
threat
0.0
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.