Type Confusion RCE in Ashlar-Vellum Cobalt CO File Parsing
Ashlar-Vellum Cobalt has a remote code execution vulnerability. Attackers can run any code on affected systems. But, the user has to visit a bad page or open a harmful file. This problem is in how CO files are parsed. There is not enough proper checking of user data, leading to a type confusion issue. Attackers can use this to run code in the current process. This was known as ZDI-CAN-24843.
Vulnerable Product | Search on Vulmon | Subscribe to Product |
---|---|---|
ashlar-vellum cobalt |
||
ashlar cobalt 1204.90 |