CVE-2025-46269: Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, Cobalt Share Heap-based Buffer Overflow
In Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share versions prior to 12.6.1204.204, the affected applications lack proper validation of user-supplied data when parsing VC6 files. This could lead to a heap-based buffer overflow. An attacker could leverage this vulnerability to execute arbitrary code in the context of the current process.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-46269?
CVE-2025-46269 is classified as a high-severity vulnerability due to its potential to cause a heap-based buffer overflow.
How do I fix CVE-2025-46269?
To mitigate CVE-2025-46269, update your Ashlar-Vellum software to version 12.6.1204.204 or later.
What applications are affected by CVE-2025-46269?
CVE-2025-46269 affects Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share versions prior to 12.6.1204.204.
What can an attacker do with CVE-2025-46269?
An attacker could exploit CVE-2025-46269 to execute arbitrary code through a heap-based buffer overflow.
Is there a workaround for CVE-2025-46269 if I cannot update immediately?
There are no official workarounds for CVE-2025-46269; updating to the latest version is recommended for protection.