CVE-2025-7981
BaseFortify
Publication date: 2025-09-17
Last updated on: 2025-09-22
Assigner: Zero Day Initiative
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| ashlar | graphite | 13.0.48 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-457 | The code uses a variable that has not been initialized, leading to unpredictable or unintended results. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability exists in Ashlar-Vellum Graphite's VC6 file parsing due to an uninitialized variable. It allows remote attackers to execute arbitrary code by exploiting the improper initialization of memory when parsing VC6 files. Exploitation requires user interaction, such as visiting a malicious page or opening a malicious file.
How can this vulnerability impact me? :
If exploited, this vulnerability can allow an attacker to execute arbitrary code with the privileges of the current process, potentially leading to full compromise of the affected system or application.