CVE-2025-2018
CVSS 3.1 Score 5.8 of 10 (medium)
Attack Complexity low
Scope changed
Integrity low
Confidentiality none
Availability none
Privileges Required none
Details
Published Mar 11, 2025
CWE ID 20
Summary
CVE-2025-2018 is a type confusion remote code execution vulnerability affecting Ashlar-Vellum Cobalt. This issue arises from insufficient validation of user-supplied data during VS file parsing. An attacker can exploit this vulnerability by tricking users into visiting a malicious page or opening a malicious file. Successful exploitation allows the attacker to execute arbitrary code in the context of the affected installation. This vulnerability, identified as ZDI-CAN-25245, can lead to serious security consequences if left unaddressed.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.