CVE-2025-52584: Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, Cobalt Share Heap-based Buffer Overflow
In Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share versions prior to 12.6.1204.204, the affected applications lack proper validation of user-supplied data when parsing XE files. This could lead to a heap-based buffer overflow. An attacker could leverage this vulnerability to execute arbitrary code in the context of the current process.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-52584?
CVE-2025-52584 has a high severity rating due to the potential for a heap-based buffer overflow that could allow remote code execution.
How do I fix CVE-2025-52584?
To mitigate CVE-2025-52584, upgrade all affected Ashlar-Vellum products to version 12.6.1204.204 or later.
Which Ashlar-Vellum products are affected by CVE-2025-52584?
CVE-2025-52584 affects Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share versions prior to 12.6.1204.204.
What could an attacker achieve by exploiting CVE-2025-52584?
An attacker exploiting CVE-2025-52584 could potentially execute arbitrary code on the target system.
Is there a workaround for CVE-2025-52584 if I can't update immediately?
Currently, there are no known workarounds for CVE-2025-52584, so updating to the latest version is strongly recommended.