CVE-2025-2016

CVSS 3.1 Score 7.5 of 10 (high)

Attack Complexity low
Availability high
Confidentiality none
Integrity none
Scope unchanged
Privileges Required none

Details

Published Mar 11, 2025
CWE ID 789

Summary

CVE-2025-2016 is a remote code execution vulnerability affecting Ashlar-Vellum Cobalt software. The issue stems from insufficient validation of user-supplied data during VC6 file parsing, leading to a type confusion condition. Attackers can exploit this vulnerability by persuading targets to visit a malicious page or open a malicious file. Successful exploitation grants the attacker the ability to execute arbitrary code within the affected process. This vulnerability, also known as ZDI-CAN-25238, poses a significant risk to users of Ashlar-Vellum Cobalt.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share