7.8
CVSSv3

CVE-2024-13047

CVSSv4: NA | CVSSv3: 7.8 | CVSSv2: NA | VMScore: 880 | EPSS: 0.00055 | KEV: Not Included
Published: 30/12/2024 Updated: 03/01/2025

Vulnerability Summary

Type Confusion RCE in Ashlar-Vellum Cobalt CO File Parsing

Ashlar-Vellum Cobalt has a remote code execution vulnerability. Attackers can run any code on affected systems. But, the user has to visit a bad page or open a harmful file. This problem is in how CO files are parsed. There is not enough proper checking of user data, leading to a type confusion issue. Attackers can use this to run code in the current process. This was known as ZDI-CAN-24843.

Vulnerable Product Search on Vulmon Subscribe to Product

ashlar-vellum cobalt

ashlar cobalt 1204.90