Junglewise Threat Intelligence

CVE-2025-65084: Ashlar-Vellum CAD Software Out-of-Bounds Write

CVE-2025-65084 · Severity: critical · CVSS 9.8 · Published 2025-11-25

Technologies: Ashlar Cobalt, Ashlar-Vellum Argon, Ashlar Cobalt Share, Ashlar Lithium, Ashlar Xenon. Vendors: Ashlar.

Executive brief

Ashlar-Vellum CAD and 3D modeling software products are affected by a security flaw that could allow an attacker to take control of a user's system. By tricking a user into opening a specially crafted file, an attacker could steal sensitive information or run unauthorized programs. This could lead to a total compromise of the workstation used for industrial design and manufacturing.

Technical details

An out-of-bounds write vulnerability (CWE-787) exists in Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share. The flaw is triggered when the application processes a specially crafted file, leading to memory corruption. An attacker can exploit this by convincing a user to open a malicious file, potentially achieving arbitrary code execution or sensitive information disclosure in the context of the current user. The vulnerability is addressed in build 12.6.1204.217 and later.

Affected products

  • Ashlar-Vellum Cobalt <= 12.6.1204.216
  • Ashlar-Vellum Xenon <= 12.6.1204.216
  • Ashlar-Vellum Argon <= 12.6.1204.216
  • Ashlar-Vellum Lithium <= 12.6.1204.216
  • Ashlar-Vellum Cobalt Share <= 12.6.1204.216

Timeline

  • 2025-11-25: advisory: Initial advisory published by CISA/NVD
  • 2026-05-12: patched: Advisory updated with revised version ranges and fix information

References

Related threats