Junglewise Threat Intelligence

CVE-2025-65087: Ashlar-Vellum CAD Products Out-of-Bounds Read in VC6 Parsing

CVE-2025-65087 · Severity: info · CVSS 8.4 · Published 2026-05-12

Technologies: Ashlar-Vellum Argon, Ashlar-Vellum Cobalt, Ashlar-Vellum Lithium, Ashlar-Vellum Cobalt Share, Ashlar-Vellum Xenon.

Executive brief

Ashlar-Vellum CAD software products, used in critical manufacturing for 3D modeling and design, are affected by a security flaw in how they handle specific file types. An attacker could trick a user into opening a malicious VC6 file, potentially leading to the theft of sensitive design data or the ability to run unauthorized code on the user's computer. This could result in a loss of intellectual property or a full system compromise within a manufacturing environment.

Technical details

An out-of-bounds read vulnerability (CWE-125) exists in multiple Ashlar-Vellum products, including Cobalt, Xenon, Argon, Lithium, and Cobalt Share. The flaw is triggered during the parsing of specially crafted VC6 files. While the primary vulnerability is an out-of-bounds read, the advisory indicates it can be leveraged for both information disclosure and arbitrary code execution. Exploitation requires a local user to open a malicious file (user interaction required). The vendor has released build 12.6.1204.217 to mitigate this issue.

Affected products

  • Ashlar-Vellum Cobalt <= 12.6.1204.216
  • Ashlar-Vellum Xenon <= 12.6.1204.216
  • Ashlar-Vellum Argon <= 12.6.1204.216
  • Ashlar-Vellum Lithium <= 12.6.1204.216
  • Ashlar-Vellum Cobalt Share <= 12.6.1204.216

Timeline

  • 2026-05-12: advisory: CISA ICSA-25-329-01 published
  • 2026-05-12: disclosed: CVE-2025-65087 published to NVD

References