7.8
CVSSv3

CVE-2023-39427

CVSSv4: NA | CVSSv3: 7.8 | CVSSv2: NA | VMScore: 880 | EPSS: 0.00073 | KEV: Not Included
Published: 26/10/2023 Updated: 21/11/2024

Vulnerability Summary

In Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share v12 SP0 Build (1204.77), the affected applications lack proper validation of user-supplied data when parsing XE files. This could lead to an out-of-bounds write. An attacker could leverage this vulnerability to execute arbitrary code in the context of the current process.

Solution


Ashlar-Vellum recommends users apply the following mitigations to help reduce risk: * Cobalt, Xenon, Lithium, and Argon share update v12 https://download.ashlar.com/v12/ Build (1204.78).
* Only open files from trusted sources.





Vulnerable Product Search on Vulmon Subscribe to Product

ashlar-vellum cobalt

ashlar-vellum xenon

ashlar-vellum argon

ashlar-vellum lithium

ashlar-vellum cobalt share

ashlar cobalt

ashlar graphite

ashlar xenon

ashlar argon

ashlar lithium