Impact
ColdFusion is vulnerable to an improper input validation flaw that can allow a low‑privileged user to execute arbitrary code in the context of the current user. The weakness is based on CWE‑20 and requires a victim to open a malicious file; the attack will change the scope of the system, giving the attacker additional privileges beyond the initial user rights.
Affected Systems
Adobe ColdFusion 2023 and Adobe ColdFusion 2025 installations are affected. No specific sub‑version information is listed, so all releases within those product lines should be considered vulnerable until a patch is applied.
Risk and Exploitability
The CVSS score of 8.4 indicates a high severity vulnerability. EPSS data are not available and the issue is not listed in the CISA KEV catalog, but the requirement for user interaction and default restriction to an administrative network zone means exploitation is less likely but still feasible, particularly in environments where administrative network traffic is not heavily monitored. The attacker would need to entice a user to open a malicious file, after which the vulnerability could elevate privileges and allow code execution.
OpenCVE Enrichment