Executive brief
Ashlar-Vellum CAD and 3D modeling software products are affected by a security flaw that could allow an attacker to take control of a computer or steal sensitive information. This occurs when the software processes a specially crafted file, potentially leading to a system crash or unauthorized code execution. Users are advised to update to the latest version to protect their design data and operational integrity.
Technical details
A heap-based buffer overflow (CWE-122) exists in multiple Ashlar-Vellum products, including Cobalt, Xenon, Argon, Lithium, and Cobalt Share. The vulnerability is triggered when the application processes malformed data, leading to memory corruption. An attacker can exploit this by enticing a user to open a specially crafted file, potentially resulting in arbitrary code execution or sensitive information disclosure. The attack requires local access and user interaction. Ashlar-Vellum recommends updating to build 12.6.1204.217 or later to mitigate this risk.
Affected products
- Ashlar-Vellum Cobalt <= 12.6.1204.216
- Ashlar-Vellum Xenon <= 12.6.1204.216
- Ashlar-Vellum Argon <= 12.6.1204.216
- Ashlar-Vellum Lithium <= 12.6.1204.216
- Ashlar-Vellum Cobalt Share <= 12.6.1204.216
Timeline
- 2025-11-25: disclosed
- 2025-11-25: advisory
- 2026-05-12: patched: Advisory updated to reflect patch version 12.6.1204.217