Impact
Adobe Campaign Classic is impacted by an incorrect authorization flaw that permits an attacker to execute arbitrary code on the system in the context of the current user. The weakness is classified as CWE-863, allowing privilege escalation without user interaction. If exploited, an attacker could run arbitrary commands, alter data, or compromise the integrity of the entire Campaign instance.
Affected Systems
Adobe Corporation – Adobe Campaign Classic. No specific version numbers are disclosed, so any installation of Adobe Campaign Classic is vulnerable until a patch that addresses this authorization issue is applied.
Risk and Exploitability
The CVSS score of 10 indicates maximum severity, while the EPSS score of less than 1% suggests a very low but non-zero exploitation probability. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is remote access via Web services or the administration interface where flawed permission checks can be bypassed, and the changed scope may grant full system control.
OpenCVE Enrichment