Executive brief
Ashlar-Vellum CAD and 3D modeling software products are affected by a security flaw that could allow an attacker to take control of a user's system. By tricking a user into opening a specially crafted file, an attacker could steal sensitive information or run unauthorized programs. This could lead to a total compromise of the workstation used for industrial design and manufacturing.
Technical details
An out-of-bounds write vulnerability (CWE-787) exists in Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share. The flaw is triggered when the application processes a specially crafted file, leading to memory corruption. An attacker can exploit this by convincing a user to open a malicious file, potentially achieving arbitrary code execution or sensitive information disclosure in the context of the current user. The vulnerability is addressed in build 12.6.1204.217 and later.
Affected products
- Ashlar-Vellum Cobalt <= 12.6.1204.216
- Ashlar-Vellum Xenon <= 12.6.1204.216
- Ashlar-Vellum Argon <= 12.6.1204.216
- Ashlar-Vellum Lithium <= 12.6.1204.216
- Ashlar-Vellum Cobalt Share <= 12.6.1204.216
Timeline
- 2025-11-25: advisory: Initial advisory published by CISA/NVD
- 2026-05-12: patched: Advisory updated with revised version ranges and fix information