CVE-2025-2019

CVSS 3.0 Score 7.8 of 10 (high)

Details

Published Mar 11, 2025
CWE ID 122

Summary

CVE-2025-2019 is a heap-based buffer overflow vulnerability affecting Ashlar-Vellum Cobalt's file parsing functionality for VC6 files. The flaw arises due to insufficient validation of user-supplied data, allowing attackers to execute arbitrary code on affected installations. Exploitation requires user interaction, such as visiting a malicious webpage or opening a malicious file. The vulnerability, also known as ZDI-CAN-25252, could lead to serious security implications.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share