CVE-2017-3066
KEV PoC largeUnauthenticated Deserialization RCE in Adobe ColdFusion (BlazeDS)
CISA: Adobe ColdFusion Deserialization Vulnerability
CVE-2017-3066 is a Java deserialization vulnerability (CWE-502) in the Apache BlazeDS library bundled with Adobe ColdFusion, which handles the product's Flex/AMF remoting functionality. An unauthenticated remote attacker can trigger it by sending crafted serialized Java objects to the server's BlazeDS message broker endpoints over the network. Successful exploitation allows arbitrary code execution with the privileges of the ColdFusion service, and the critical CVSS 3.1 score of 9.8 reflects that no privileges, user interaction, or special conditions are required. Users of Adobe ColdFusion 2016 Update 3 and earlier, ColdFusion 11 Update 11 and earlier, and ColdFusion 10 Update 22 and earlier are affected. The flaw is being actively exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2025-02-24 alongside an Oracle flaw, its EPSS probability of exploitation within 30 days is 90.6% (100th percentile), and a public proof-of-concept exploit is available on Exploit-DB (43993).
What to do: Update all ColdFusion 10, 11, and 2016 servers beyond the affected update levels per Adobe's vendor guidance, or discontinue use of the product if mitigations are unavailable, as required by the CISA KEV listing. Until patched, restrict or block network access to the BlazeDS/AMF remoting endpoints (the /flex2gateway endpoints) at the firewall or web server layer, since these are the attack surface for this flaw, and review access logs for anomalous requests to them. A public proof-of-concept (Exploit-DB 43993) shows unauthenticated exploitation, so treat exposed instances as high-priority; ransomware use is currently listed as unknown.
| adobe coldfusion | ColdFusion 2016 Update 3 and earlier |
| adobe coldfusion | ColdFusion 11 Update 11 and earlier |
| adobe coldfusion | ColdFusion 10 Update 22 and earlier |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Adobe ColdFusion 2016 Update 3 and earlier, ColdFusion 11 update 11 and earlier, ColdFusion 10 Update 22 and earlier have a Java deserialization vulnerability in the Apache BlazeDS library. Successful exploitation could lead to arbitrary code execution.
- Affected
- Adobe ColdFusion
- Required action
- Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- adobe
- Products
- coldfusion
- Weakness
- CWE-502
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H