Impact
Adobe Campaign Classic contains an OS command injection vulnerability caused by improper neutralization of special elements. Attackers can inject crafted commands that are executed with the privileges of the current user, potentially enabling arbitrary code execution. The flaw is exploitable without any user interaction and a scope change indicates that impact may extend beyond the originally affected components.
Affected Systems
Adobe Campaign Classic versions 7.4.1 (9383), 7.4.2 (9390‑9391), 7.4.3 (9394‑9399), and 7.4.4 (9400) are affected. All installations of the product are vulnerable unless patched, and these specific sub‑versions are explicitly listed as impacted. The vulnerability also applies to deployments on Linux and Windows operating systems.
Risk and Exploitability
The CVSS score of 10 marks it as critical, and the EPSS score of 0.03505% indicates a very low yet non‑zero likelihood of exploitation; the absence of a KEV listing does not reduce the risk. The likely attack vector is remote, via crafted input to the application’s command interface or API, enabling a threat actor to execute arbitrary OS commands. Because exploitation does not require interaction, exposure to external traffic makes the vulnerability highly actionable.
OpenCVE Enrichment