Impact
A heap‑based buffer overflow exists in Adobe ColdFusion. The flaw can allow execution of arbitrary code in the context of the user that owns the ColdFusion service. The vulnerability is identified as CWE‑122. An attacker may cause the application to write outside the bounds of a heap object, potentially leading to code execution. The exploit does not need user interaction; however, the actual exploitation requires conditions that lie beyond the attacker’s direct control, so it is not trivially triggerable.
Affected Systems
The affected products are Adobe ColdFusion 2023 and Adobe ColdFusion 2025, with no specific version ranges provided. All installations of these products are vulnerable until a vendor patch is applied.
Risk and Exploitability
The CVSS score of 8.1 classifies this flaw as High severity, indicating that exploitation could lead to complete compromise of the affected system. EPSS information is not available, and the vulnerability is not listed in the CISA KEV catalog, which suggests a lower documented exploitation rate, though the lack of EPSS data prevents a precise estimation of exploit probability. The flaw can be triggered without user interaction; the likely attack vector therefore involves remote exploitation of a ColdFusion service that is reachable over the network. If the conditions to trigger the overflow are satisfied, the attacker could gain local execution rights, effectively escalating privileges within the ColdFusion environment.
OpenCVE Enrichment