Junglewise Threat Intelligence

CVE-2025-65088: Ashlar-Vellum CAD Products Out-of-Bounds Read in VC6 Parsing

CVE-2025-65088 · Severity: info · CVSS 8.4 · Published 2026-05-12

Technologies: Ashlar-Vellum Cobalt, Ashlar-Vellum Cobalt Share, Ashlar-Vellum Lithium, Ashlar-Vellum Argon, Ashlar-Vellum Xenon.

Executive brief

Ashlar-Vellum CAD and 3D modeling software is affected by a security flaw that occurs when processing specific design files. An attacker could trick a user into opening a malicious VC6 file, potentially leading to the theft of sensitive information or the unauthorized execution of commands on the user's computer. This could compromise proprietary engineering designs or allow a foothold for further network intrusion.

Technical details

An Out-of-Bounds Read (CWE-125) exists in multiple Ashlar-Vellum products, including Cobalt, Xenon, Argon, Lithium, and Cobalt Share. The vulnerability is triggered during the parsing of specially crafted VC6 files. An attacker can exploit this by convincing a user to open a malicious file, leading to memory corruption. This can result in the disclosure of sensitive memory contents or the execution of arbitrary code in the context of the current user. The vendor has released build 12.6.1204.217 to address this issue.

Affected products

  • Ashlar-Vellum Cobalt <=12.6.1204.216
  • Ashlar-Vellum Xenon <=12.6.1204.216
  • Ashlar-Vellum Argon <=12.6.1204.216
  • Ashlar-Vellum Lithium <=12.6.1204.216
  • Ashlar-Vellum Cobalt Share <=12.6.1204.216

Timeline

  • 2026-05-12: advisory: CISA ICSA-25-329-01 published
  • 2026-05-12: disclosed: CVE-2025-65088 published to NVD

References