Executive brief
Ashlar-Vellum CAD software products, used in critical manufacturing for 3D modeling and design, are affected by a security flaw in how they handle specific file types. An attacker could trick a user into opening a malicious VC6 file, potentially leading to the theft of sensitive design data or the ability to run unauthorized code on the user's computer. This could result in a loss of intellectual property or a full system compromise within a manufacturing environment.
Technical details
An out-of-bounds read vulnerability (CWE-125) exists in multiple Ashlar-Vellum products, including Cobalt, Xenon, Argon, Lithium, and Cobalt Share. The flaw is triggered during the parsing of specially crafted VC6 files. While the primary vulnerability is an out-of-bounds read, the advisory indicates it can be leveraged for both information disclosure and arbitrary code execution. Exploitation requires a local user to open a malicious file (user interaction required). The vendor has released build 12.6.1204.217 to mitigate this issue.
Affected products
- Ashlar-Vellum Cobalt <= 12.6.1204.216
- Ashlar-Vellum Xenon <= 12.6.1204.216
- Ashlar-Vellum Argon <= 12.6.1204.216
- Ashlar-Vellum Lithium <= 12.6.1204.216
- Ashlar-Vellum Cobalt Share <= 12.6.1204.216
Timeline
- 2026-05-12: advisory: CISA ICSA-25-329-01 published
- 2026-05-12: disclosed: CVE-2025-65087 published to NVD