PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-65084 Ashlar-Vellum CVE debrief

An Out-of-Bounds Write vulnerability (CWE-787) affects Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share versions 12.6.1204.216 and prior. The vulnerability allows an attacker to disclose information or execute arbitrary code. The CVSS 3.1 score of 7.8 (HIGH) reflects local attack vector, low attack complexity, no privileges required, and user interaction required, with high impacts to confidentiality, integrity, and availability. The vendor has released build 12.6.1204.217 to address this issue. This vulnerability was initially published on November 25, 2025, and subsequently updated on May 12, 2026 (Update A), which revised the mitigation section, affected product versions, and added CVE identifiers.

Vendor
Ashlar-Vellum
Product
Cobalt
CVSS
HIGH 7.8
CISA KEV
Not listed in stored evidence
Original CVE published
2025-11-25
Original CVE updated
2026-05-12
Advisory published
2025-11-25
Advisory updated
2026-05-12

Who should care

Organizations using Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, or Cobalt Share for CAD and 3D modeling, particularly in industrial or engineering environments. System administrators managing workstations with these applications installed. Security teams responsible for vulnerability management in OT/ICS environments.

Technical summary

The vulnerability is an Out-of-Bounds Write (CWE-787) present in multiple Ashlar-Vellum CAD and 3D modeling products. The affected versions (12.6.1204.216 and prior) can be exploited to achieve information disclosure or arbitrary code execution. The attack requires local access and user interaction, with no privileges required. The CVSS 3.1 vector (AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H) indicates that successful exploitation results in complete compromise of confidentiality, integrity, and availability on the affected system. The vendor has addressed this in build 12.6.1204.217.

Defensive priority

HIGH

Recommended defensive actions

  • Update Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, or Cobalt Share to build 12.6.1204.217 or later
  • Apply vendor-provided patches as the primary remediation
  • Follow CISA ICS recommended practices for defense-in-depth strategies
  • Implement network segmentation for industrial control systems where these applications are deployed
  • Restrict user privileges and enforce principle of least privilege
  • Train users to recognize and avoid phishing attacks that could deliver malicious files
  • Monitor for anomalous process execution or file system activity from affected applications

Evidence notes

Source: CISA CSAF advisory ICSA-25-329-01. Vendor confirmed: Ashlar-Vellum. Affected products: Cobalt, Xenon, Argon, Lithium, Cobalt Share. Affected versions: 12.6.1204.216 and prior. Fix version: 12.6.1204.217. CWE-787 (Out-of-bounds Write). CVSS 3.1: 7.8 (AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).

Official resources

2025-11-25