Executive brief
Ashlar-Vellum Cobalt is a design and visualization software used for engineering and technical drawings. A heap buffer overflow vulnerability in its VS file parser allows attackers to execute arbitrary code when a user opens a malicious file, potentially compromising the integrity of systems and enabling unauthorized access to sensitive design data or system credentials.
Technical details
A heap-based buffer overflow vulnerability exists in Ashlar-Vellum Cobalt's VS file parser due to insufficient validation of user-supplied data length before copying to a heap buffer. The attack vector is local (requires user interaction to open a malicious VS file), but remote delivery is possible via social engineering or malicious pages. An attacker can craft a specially formatted VS file that, when opened by a victim, triggers the overflow and achieves arbitrary code execution in the context of the Cobalt process. The vulnerability was patched in version 12.6.1204.210.
Affected products
- Ashlar-Vellum Cobalt before 12.6.1204.210
Timeline
- 2025-11-11: disclosed: Vulnerability reported to vendor
- 2026-08-24: patched: Fixed in version 12.6.1204.210
- 2026-08-24: advisory: Public advisory published (ZDI-26-587, CVE-2026-19781)