PatchSiren cyber security CVE debrief
CVE-2025-65084 Ashlar-Vellum CVE debrief
An Out-of-Bounds Write vulnerability (CWE-787) affects Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share versions 12.6.1204.216 and prior. The vulnerability allows an attacker to disclose information or execute arbitrary code. The CVSS 3.1 score of 7.8 (HIGH) reflects local attack vector, low attack complexity, no privileges required, and user interaction required, with high impacts to confidentiality, integrity, and availability. The vendor has released build 12.6.1204.217 to address this issue. This vulnerability was initially published on November 25, 2025, and subsequently updated on May 12, 2026 (Update A), which revised the mitigation section, affected product versions, and added CVE identifiers.
- Vendor
- Ashlar-Vellum
- Product
- Cobalt
- CVSS
- HIGH 7.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2025-11-25
- Original CVE updated
- 2026-05-12
- Advisory published
- 2025-11-25
- Advisory updated
- 2026-05-12
Who should care
Organizations using Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, or Cobalt Share for CAD and 3D modeling, particularly in industrial or engineering environments. System administrators managing workstations with these applications installed. Security teams responsible for vulnerability management in OT/ICS environments.
Technical summary
The vulnerability is an Out-of-Bounds Write (CWE-787) present in multiple Ashlar-Vellum CAD and 3D modeling products. The affected versions (12.6.1204.216 and prior) can be exploited to achieve information disclosure or arbitrary code execution. The attack requires local access and user interaction, with no privileges required. The CVSS 3.1 vector (AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H) indicates that successful exploitation results in complete compromise of confidentiality, integrity, and availability on the affected system. The vendor has addressed this in build 12.6.1204.217.
Defensive priority
HIGH
Recommended defensive actions
- Update Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, or Cobalt Share to build 12.6.1204.217 or later
- Apply vendor-provided patches as the primary remediation
- Follow CISA ICS recommended practices for defense-in-depth strategies
- Implement network segmentation for industrial control systems where these applications are deployed
- Restrict user privileges and enforce principle of least privilege
- Train users to recognize and avoid phishing attacks that could deliver malicious files
- Monitor for anomalous process execution or file system activity from affected applications
Evidence notes
Source: CISA CSAF advisory ICSA-25-329-01. Vendor confirmed: Ashlar-Vellum. Affected products: Cobalt, Xenon, Argon, Lithium, Cobalt Share. Affected versions: 12.6.1204.216 and prior. Fix version: 12.6.1204.217. CWE-787 (Out-of-bounds Write). CVSS 3.1: 7.8 (AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H).
Sources and references
Verified primary and authoritative sources
-
CVE-2025-65084 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-65084
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-65084 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-65084
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-329-01.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-329-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ncas/tips/ST04-014
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.