ZeroHour

CVE-2017-3066

KEV PoC large

Unauthenticated Deserialization RCE in Adobe ColdFusion (BlazeDS)

CISA: Adobe ColdFusion Deserialization Vulnerability

CVSS 3.1
9.8 critical
EPSS
91%p100
Published
()
KEV added
AI analysis

CVE-2017-3066 is a Java deserialization vulnerability (CWE-502) in the Apache BlazeDS library bundled with Adobe ColdFusion, which handles the product's Flex/AMF remoting functionality. An unauthenticated remote attacker can trigger it by sending crafted serialized Java objects to the server's BlazeDS message broker endpoints over the network. Successful exploitation allows arbitrary code execution with the privileges of the ColdFusion service, and the critical CVSS 3.1 score of 9.8 reflects that no privileges, user interaction, or special conditions are required. Users of Adobe ColdFusion 2016 Update 3 and earlier, ColdFusion 11 Update 11 and earlier, and ColdFusion 10 Update 22 and earlier are affected. The flaw is being actively exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2025-02-24 alongside an Oracle flaw, its EPSS probability of exploitation within 30 days is 90.6% (100th percentile), and a public proof-of-concept exploit is available on Exploit-DB (43993).

What to do: Update all ColdFusion 10, 11, and 2016 servers beyond the affected update levels per Adobe's vendor guidance, or discontinue use of the product if mitigations are unavailable, as required by the CISA KEV listing. Until patched, restrict or block network access to the BlazeDS/AMF remoting endpoints (the /flex2gateway endpoints) at the firewall or web server layer, since these are the attack surface for this flaw, and review access logs for anomalous requests to them. A public proof-of-concept (Exploit-DB 43993) shows unauthenticated exploitation, so treat exposed instances as high-priority; ransomware use is currently listed as unknown.

Affected
adobe coldfusionColdFusion 2016 Update 3 and earlier
adobe coldfusionColdFusion 11 Update 11 and earlier
adobe coldfusionColdFusion 10 Update 22 and earlier
Estimated exposure
largetens of thousands of internet-exposed ColdFusion servers (10k-100k range) — ColdFusion has a large installed base of enterprise and government web applications, and public internet scans have long shown tens of thousands of externally reachable ColdFusion servers, many of which run legacy ColdFusion 10, 11, and…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Adobe ColdFusion 2016 Update 3 and earlier, ColdFusion 11 update 11 and earlier, ColdFusion 10 Update 22 and earlier have a Java deserialization vulnerability in the Apache BlazeDS library. Successful exploitation could lead to arbitrary code execution.

CISA Known Exploited Vulnerability
Affected
Adobe ColdFusion
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
adobe
Products
coldfusion
Weakness
CWE-502
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news