SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2022-35710

Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user.

CRITICAL 9.8EPSS 42.6%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 42.6%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.

Description

Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier) are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction, the vulnerability is triggered when a crafted network packet is sent to the server.

CVSS 3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
42.58% probability · 99th percentile
CISA KEV
Not listed
Weakness
CWE-121, CWE-787
Affected
adobe/coldfusion
Source
psirt@adobe.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.