Impact
Adobe Campaign Classic is vulnerable to an OS command injection flaw that allows an attacker to execute arbitrary code in the context of the current user. The vulnerability arises from improper neutralization of special elements used in an OS command and can be exploited without any user interaction. Consequently, successful exploitation results in the compromise of the application’s process and, if unmitigated, could extend to the underlying operating system depending on user privileges. The vendor has classified the impact scope as changed, indicating that the flaw can affect components beyond the initially intended boundaries.
Affected Systems
All installations of Adobe Campaign Classic are impacted; the advisory does not specify version ranges, so any deployed version without a pending patch should be considered vulnerable.
Risk and Exploitability
The CVSS score of 10 marks this flaw as critical, and while an EPSS score is not provided, the lack of a KEV listing does not diminish the inherent risk. Based on the description, the likely attack vector is a remote web‑based exploit targeting the Campaign Classic application’s CLI interface, permitting an attacker to send a crafted command without needing interaction. The scope change plus the high severity indicate that once exploited, an attacker could gain significant control over the affected system.
OpenCVE Enrichment