7.8
CVSSv3

CVE-2024-13046

CVSSv4: NA | CVSSv3: 7.8 | CVSSv2: NA | VMScore: 880 | EPSS: 0.00069 | KEV: Not Included
Published: 30/12/2024 Updated: 03/01/2025

Vulnerability Summary

Remote Code Execution via CO File Parsing in Ashlar-Vellum Cobalt

Ashlar-Vellum Cobalt has a remote code execution vulnerability when parsing CO files. This lets remote attackers run arbitrary code on affected systems. The target user must visit a harmful page or open a harmful file for this to happen. The flaw is in how CO files are parsed. The problem is due to not properly checking user-supplied data. This can lead to writing outside the allocated buffer. Attackers can use this vulnerability to execute code in the current process context. It was identified as ZDI-CAN-24867.

Vulnerable Product Search on Vulmon Subscribe to Product

ashlar-vellum cobalt

ashlar cobalt 1204.90