Impact
Adobe Campaign Classic (ACC) suffers from an improper neutralization of directives in code that is evaluated at runtime, allowing an attacker to inject and execute malicious commands. This flaw results in arbitrary code execution with the privileges of the current user, which can be a low‑privileged account. The vulnerability does not require user interaction and the scope is changed, meaning privilege escalation is possible if the compromised account has higher rights. The weakness is identified as CWE‑95.
Affected Systems
Adobe Campaign Classic (ACC) is the affected product. The advisory does not list specific version numbers, so all deployments of ACC are potentially vulnerable until a patch is applied. Because no version information is provided, perform a product inventory check against the Adobe security advisory reference for any applicable releases.
Risk and Exploitability
The CVSS score of 9.6 indicates critical severity. EPSS data is not available, so the exploitation probability is unknown, but the flaw is actively exploitable in the field as the attack does not need user interaction and the scope change allows escalation. The product is not listed in CISA's KEV catalog, however the high CVSS and the lack of a user interaction requirement mean that zero‑day exploitation is likely and could occur at any time. An attacker that can send crafted requests or otherwise inject code into ACC can execute arbitrary commands on the server, compromising confidentiality, integrity, and availability.
OpenCVE Enrichment