Home

Description

In Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share versions prior to 12.6.1204.204, the affected applications lack proper validation of user-supplied data when parsing CO files. This could lead to an out-of-bounds write. An attacker could leverage this vulnerability to execute arbitrary code in the context of the current process.

PUBLISHED Reserved 2025-07-08 | Published 2025-08-18 | Updated 2025-08-19 | Assigner icscert




HIGH: 8.4CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

HIGH: 7.8CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Problem types

CWE-787 Out-of-bounds Write

Product status

Default status
unaffected

Any version before 12.6.1204.204
affected

Default status
unaffected

Any version before 12.6.1204.204
affected

Default status
unaffected

Any version before 12.6.1204.204
affected

Default status
unaffected

Any version before 12.6.1204.204
affected

Default status
unaffected

Any version before 12.6.1204.204
affected

Credits

Michael Heinzl reported these vulnerabilities to CISA. finder

References

www.cisa.gov/news-events/ics-advisories/icsa-25-224-01

cve.org (CVE-2025-53705)

nvd.nist.gov (CVE-2025-53705)

Download JSON