Impact
Ashlar‑Vellum Cobalt has a heap‑based buffer overflow when parsing VS files. The flaw occurs because the program does not check the length of user‑supplied data before copying it into a heap buffer, which matches CWE‑122. An attacker can exploit this by delivering a specially crafted VS file or by loading a malicious page that triggers the parsing routine, enabling the execution of arbitrary code in the context of the Cobalt process.
Affected Systems
The vulnerability affects all installations of Ashlar‑Vellum Cobalt that process VS files. No specific version range is provided, so any Cobalt instance that accepts VS file input is potentially impacted. The vendor identified is Ashlar‑Vellum, product Cobalt.
Risk and Exploitability
The CVSS base score of 7.8 indicates a high severity. The EPSS score is < 1%, and the lack of a KEV listing suggests no known public exploitation yet. Exploitation requires user interaction: the target must visit a malicious web page or open a malicious VS file, giving the attacker the opportunity to trigger the overflow. Because the attack vector is remote and only requires the file to be processed, the risk remains significant for exposed installations.
OpenCVE Enrichment