Published advisory · ZDI-26-587

Ashlar-Vellum Cobalt VS File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability

Published Rocco Calvi
CVSS severity 7.8/ 10.0 · High AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Vulnerability analysis

This vulnerability allows an attacker to execute code in the context of Ashlar-Vellum Cobalt after a user opens a malicious VS file or visits a malicious page.

The VS file parser copies attacker-controlled data into a heap-based buffer without first validating its length, resulting in a heap-based buffer overflow. Ashlar-Vellum fixed the issue in version 12.6.1204.210.

Disclosure timeline

  1. Vulnerability reported to vendor
  2. Coordinated public release of advisory
  3. Advisory updated

References