Impact
The flaw is an uncontrolled search path element that can allow an attacker to execute arbitrary code in the context of the user that opens a malicious file. The weakness is identified as CWE‑427 and it changes the scope of the vulnerability, allowing the execution to occur with the privileges of the user who interacts with the file. The description specifies that the attack requires user interaction: a victim must open a crafted file for the exploit to succeed.
Affected Systems
ColdFusion products from Adobe, specifically versions 2025.9, 2023.20 and all earlier releases. Any installation running the affected code base is vulnerable. The vulnerability applies to the ColdFusion runtime component that processes user‑supplied files.
Risk and Exploitability
The CVSS score of 8.2 classifies this as a high‑severity flaw. The EPSS score is 0.00158, indicating a very low but non‑zero probability of exploitation, and the vulnerability is not listed in CISA’s KEV catalog. The attack vector is inferred to be a user‑initiated action, such as opening a malicious attachment or accessing a specially crafted web resource. Because the flaw relies on user interaction, it is less likely to be exploited remotely, but the potential for arbitrary code execution with the victim’s privileges makes it a serious concern for environments where users have the ability to download or open files.
OpenCVE Enrichment