Impact
Adobe ColdFusion is vulnerable to Improper Input Validation, allowing a low‑privileged attacker to gain unauthorized read and write access after a victim opens a malicious file. The flaw changes scope, enabling the attacker to elevate privileges on the affected system.
Affected Systems
The vulnerability impacts Adobe ColdFusion 2023 and Adobe ColdFusion 2025 releases. No specific version range is provided in the advisory, so all releases of these products are considered potentially affected.
Risk and Exploitability
The CVSS score of 8.7 indicates a high severity, while the EPSS score of less than 1% shows a low probability of exploitation at this time. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires user interaction in that the victim must open a malicious file, suggesting the attack vector is likely a social‑engineering or phishing approach that delivers a crafted file to the user.
OpenCVE Enrichment