CVE-2025-65088 PUBLISHED

Out-of-bounds read in Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, Cobalt Share

Assigner: icscert
Reserved: 17.11.2025 Published: 12.05.2026 Updated: 12.05.2026

An Out-of-Bounds Read vulnerability is present in Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share versions 12.6.1204.216 and prior that could allow an attacker to disclose information or execute arbitrary code when a specially crafted VC6 file is being parsed.

Metrics

CVSS Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
CVSS Score: 8.4

Product Status

Vendor Ashlar-Vellum
Product Cobalt
Versions Default: unaffected
  • affected from 0 to 12.6.1204.216 (incl.)
Vendor Ashlar-Vellum
Product Xenon
Versions Default: unaffected
  • affected from 0 to 12.6.1204.216 (incl.)
Vendor Ashlar-Vellum
Product Argon
Versions Default: unaffected
  • affected from 0 to 12.6.1204.216 (incl.)
Vendor Ashlar-Vellum
Product Lithium
Versions Default: unaffected
  • affected from 0 to 12.6.1204.216 (incl.)
Vendor Ashlar-Vellum
Product Cobalt Share
Versions Default: unaffected
  • affected from 0 to 12.6.1204.216 (incl.)

Solutions

Ashlar-Vellum recommends users update to build 12.6.1204.217 and later.

Credits

  • Michael Heinzl reported these vulnerabilities to CISA. finder

References

Problem Types

  • CWE-125 Out-of-bounds read CWE