CVE-2025-7978: (0Day) Ashlar-Vellum Graphite VC6 File Parsing Uninitialized Variable Remote Code Execution Vulnerability
Ashlar-Vellum Graphite VC6 File Parsing Uninitialized Variable Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Graphite. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
The specific flaw exists within the parsing of VC6 files. The issue results from the lack of proper initialization of memory prior to accessing it. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-25459.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-7978?
CVE-2025-7978 is classified as a critical vulnerability due to its potential for remote code execution.
How do I fix CVE-2025-7978?
To mitigate CVE-2025-7978, users should update Ashlar-Vellum Graphite to the latest version that addresses this vulnerability.
What types of exploitation are possible with CVE-2025-7978?
CVE-2025-7978 can be exploited to execute arbitrary code remotely, requiring user interaction to trigger the vulnerability.
Which versions of Ashlar-Vellum Graphite are affected by CVE-2025-7978?
CVE-2025-7978 affects all versions of Ashlar-Vellum Graphite prior to the security patch release.
Is user interaction necessary to exploit CVE-2025-7978?
Yes, exploitation of CVE-2025-7978 requires user interaction to execute the malicious payload.