CVE-2023-39427: Ashlar-Vellum Cobalt, Xenon, Argon, Lithium Out-of-bounds Write
In Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share v12 SP0 Build (1204.77), the affected applications lack proper validation of user-supplied data when parsing XE files. This could lead to an out-of-bounds write. An attacker could leverage this vulnerability to execute arbitrary code in the context of the current process.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the vulnerability ID for this security issue?
The vulnerability ID for this security issue is CVE-2023-39427.
What is the severity of CVE-2023-39427?
The severity of CVE-2023-39427 is high.
Which software applications are affected by CVE-2023-39427?
Ashlar Cobalt, Ashlar Graphite, Ashlar Xenon, Ashlar Argon, and Ashlar Lithium are affected by CVE-2023-39427.
What is the vulnerability description for CVE-2023-39427?
CVE-2023-39427 is an out-of-bounds write vulnerability in Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share v12 SP0 Build (1204.77) that occurs due to lack of proper validation of user-supplied data when parsing XE files.
How can an attacker exploit CVE-2023-39427?
An attacker can exploit CVE-2023-39427 to execute arbitrary code on a vulnerable system.