CVE-2025-2020
CVSS 3.1 Score 7.1 of 10 (high)
Details
Published Mar 11, 2025
CWE ID 347
Summary
CVE-2025-2020 is a remote code execution vulnerability affecting Ashlar-Vellum Cobalt software. This issue arises from insufficient validation of user-supplied data during VC6 file parsing, leading to an out-of-bounds write. An attacker can exploit this vulnerability by crafting a malicious file or luring the target to a malicious webpage, resulting in arbitrary code execution in the context of the current process. This vulnerability, previously identified as ZDI-CAN-25254, poses a significant risk to users of Ashlar-Vellum Cobalt.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Cisco Secure Client
Affected Vendors
- Cisco