Impact
An out‑of‑bounds read vulnerability exists in Ashlar‑Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share builds 12.6.1204.216 and earlier. When a specially crafted VC6 file is parsed, the software reads beyond the intended memory bounds, which can expose sensitive information or enable an attacker to execute arbitrary code. The weakness corresponds to CWE‑125.
Affected Systems
Affected products are Ashlar‑Vellum Argon, Cobalt, Cobalt Share, Lithium, and Xenon. All releases up to and including build 12.6.1204.216 are vulnerable; the vulnerability was fixed in build 12.6.1204.217 and later.
Risk and Exploitability
The CVSS score of 8.4 indicates a high‑severity flaw. No EPSS information is available and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector involves an attacker supplying a malicious VC6 file that is processed by the affected application, potentially allowing local or, if file processing occurs under elevated privileges, remote code execution. Successful exploitation requires the file to be parsed by the vulnerable software, which could be achieved through normal operating procedures that accept user‑supplied files.
OpenCVE Enrichment