Impact
ColdFusion is vulnerable to an OS Command Injection flaw that allows a low‑privileged attacker to pre‑process special elements used in an operating‑system command, resulting in a bypass of the platform’s security controls. The flaw can be exploited without user interaction and can lead to unauthorized write access to system resources.
Affected Systems
Adobe ColdFusion 2023 and Adobe ColdFusion 2025 are affected. Based on the description, it is inferred that the vulnerable function is exposed through a web interface; however, the exact exposure mechanism is not explicitly detailed in the provided data.
Risk and Exploitability
The vulnerability has a CVSS score of 7.7 and an EPSS score of less than 1 %. It is not currently listed in the CISA KEV catalog. Based on the description, it is inferred that exploitation can be achieved remotely by targeting the web interface, and the low‑privilege attacker can use the vulnerability to escape the intended sandbox and gain write permissions, effectively escalating privileges on the affected system.
OpenCVE Enrichment