PoC Index

CVE-2017-3066

KEVHIGH 10.0EPSS 90.6%

Adobe ColdFusion 2016 Update 3 and earlier, ColdFusion 11 update 11 and earlier, ColdFusion 10 Update 22 and earlier have a Java deserialization vulnerability in the Apache BlazeDS library. Successful exploitation could lead to arbitrary code execution.

CVSS v3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS v2.0
10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
EPSS
90.60% chance of exploitation in the next 30 days, 100th percentile
CISA KEV
added 2025-02-24
Published
2017-04-27
Updated
2025-10-21

Proof-of-concept exploits (4)

ExploitDB entries (1)

Vulhub environments (1)

References

Related