CVE-2025-65087

An Out-of-Bounds Read vulnerability is present in Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share versions 12.6.1204.216 and prior that could allow an attacker to disclose information or execute arbitrary code when a specially crafted VC6 file is being parsed.
References
Link Resource
https://www.cisa.gov/news-events/ics-advisories/icsa-25-329-01 Third Party Advisory US Government Resource
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:ashlar:argon:*:*:*:*:*:*:*:*
cpe:2.3:a:ashlar:cobalt:*:*:*:*:*:*:*:*
cpe:2.3:a:ashlar:cobalt_share:*:*:*:*:*:*:*:*
cpe:2.3:a:ashlar:lithium:*:*:*:*:*:*:*:*
cpe:2.3:a:ashlar:xenon:*:*:*:*:*:*:*:*

History

14 May 2026, 14:57

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.8
CPE cpe:2.3:a:ashlar:argon:*:*:*:*:*:*:*:*
cpe:2.3:a:ashlar:lithium:*:*:*:*:*:*:*:*
cpe:2.3:a:ashlar:cobalt:*:*:*:*:*:*:*:*
cpe:2.3:a:ashlar:xenon:*:*:*:*:*:*:*:*
cpe:2.3:a:ashlar:cobalt_share:*:*:*:*:*:*:*:*
References () https://www.cisa.gov/news-events/ics-advisories/icsa-25-329-01 - () https://www.cisa.gov/news-events/ics-advisories/icsa-25-329-01 - Third Party Advisory, US Government Resource
First Time Ashlar argon
Ashlar xenon
Ashlar cobalt
Ashlar lithium
Ashlar
Ashlar cobalt Share

12 May 2026, 21:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-12 21:16

Updated : 2026-05-14 14:57


NVD link : CVE-2025-65087

Mitre link : CVE-2025-65087

CVE.ORG link : CVE-2025-65087


JSON object : View

Products Affected

ashlar

  • cobalt
  • argon
  • xenon
  • lithium
  • cobalt_share
CWE
CWE-125

Out-of-bounds Read