ZDI-25-720: (0Day) Ashlar-Vellum Cobalt CO File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Cobalt. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of CO files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated data structure. An attacker can leverage this vulnerability to execute code in the context of the current process.
Other sources
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ashlar-Vellum Cobalt. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2025-8003.
— ZDI
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-25-720?
The severity of ZDI-25-720 is classified as critical due to its potential to allow remote code execution.
How do I fix ZDI-25-720?
To fix ZDI-25-720, ensure that you update Ashlar-Vellum Cobalt to the latest version provided by the vendor that addresses this vulnerability.
What types of attacks can ZDI-25-720 be used for?
ZDI-25-720 can be exploited to conduct remote code execution attacks by tricking users into visiting malicious pages or opening malicious files.
Is user interaction required to exploit ZDI-25-720?
Yes, user interaction is required to exploit ZDI-25-720, as the target must either visit a malicious webpage or open a compromised file.
Which software is affected by ZDI-25-720?
ZDI-25-720 affects installations of Ashlar-Vellum Cobalt.