Executive brief
Ashlar-Vellum CAD and 3D modeling software is susceptible to a security flaw when processing specific file types. If a user is tricked into opening a maliciously crafted VC6 file, an attacker could gain the ability to run unauthorized code on the user's computer. This could lead to a total compromise of the workstation, including data theft or the installation of malware.
Technical details
An out-of-bounds write vulnerability (CWE-787) exists in multiple Ashlar-Vellum products, including Cobalt, Xenon, Argon, Lithium, and Cobalt Share. The flaw is triggered during the parsing of VC6 files. An attacker can exploit this by providing a specially crafted file to a user; when the application attempts to process the file, it writes data outside the intended buffer boundaries. This can lead to arbitrary code execution in the context of the current user. The vulnerability requires user interaction (opening a file) and is accessible via a local attack vector. Ashlar-Vellum recommends updating to build 12.6.1204.217 or later to remediate the issue.
Affected products
- Ashlar-Vellum Cobalt <=12.6.1204.216
- Ashlar-Vellum Xenon <=12.6.1204.216
- Ashlar-Vellum Argon <=12.6.1204.216
- Ashlar-Vellum Lithium <=12.6.1204.216
- Ashlar-Vellum Cobalt Share <=12.6.1204.216
Timeline
- 2026-05-12: advisory: CISA ICS Advisory ICSA-25-329-01 published
- 2026-05-12: disclosed: CVE-2025-65086 published to NVD