CVE-2025-41392: Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, Cobalt Share Out-of-bounds Read
In Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share versions prior to 12.6.1204.204, the affected applications lack proper validation of user-supplied data when parsing AR files. This could lead to an out-of-bounds read. An attacker could leverage this vulnerability to execute arbitrary code in the context of the current process.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-41392?
CVE-2025-41392 has been classified as a high severity vulnerability due to the potential for an out-of-bounds read.
How do I fix CVE-2025-41392?
To fix CVE-2025-41392, update Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, or Cobalt Share to version 12.6.1204.204 or later.
What products are affected by CVE-2025-41392?
CVE-2025-41392 affects Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share versions prior to 12.6.1204.204.
What does CVE-2025-41392 exploit?
CVE-2025-41392 exploits a lack of proper validation of user-supplied data when parsing AR files.
What could happen if CVE-2025-41392 is exploited?
If exploited, CVE-2025-41392 could lead to an out-of-bounds read, which may allow an attacker to access sensitive data.