Junglewise Threat Intelligence

CVE-2017-3066: Adobe ColdFusion Deserialization Vulnerability

CVE-2017-3066 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2025-02-24

Technologies: Adobe ColdFusion. Vendors: Adobe.

Executive brief

Adobe ColdFusion contains a Java deserialization vulnerability in the Apache BlazeDS library. Successful exploitation allows an unauthenticated remote attacker to execute arbitrary code on the affected system.

Affected products

  • Adobe ColdFusion 2016 Update 3 and earlier
  • Adobe ColdFusion 11 Update 11 and earlier
  • Adobe ColdFusion 10 Update 22 and earlier

Timeline

  • 2017-04-25: advisory: Original Adobe advisory APSB17-14 published
  • 2025-02-24: kev added: Added to CISA Known Exploited Vulnerabilities (KEV) catalog
  • 2025-02-24: exploited: Confirmed as exploited in the wild per CISA KEV entry

Related threats