AI description
CVE-2017-3066 is a vulnerability that allows remote code execution due to Java deserialization issues in the Apache BlazeDS library used by Adobe ColdFusion. Affected versions include Adobe ColdFusion 2016 Update 3 and earlier, ColdFusion 11 Update 11 and earlier, and ColdFusion 10 Update 22 and earlier. Exploitation of this vulnerability could allow an attacker to execute arbitrary code on the affected system. The vulnerability was identified and reported in 2017. As of February 24, 2025, CISA added CVE-2017-3066 to its Known Exploited Vulnerabilities Catalog due to evidence of active exploitation.
- Description
- Adobe ColdFusion 2016 Update 3 and earlier, ColdFusion 11 update 11 and earlier, ColdFusion 10 Update 22 and earlier have a Java deserialization vulnerability in the Apache BlazeDS library. Successful exploitation could lead to arbitrary code execution.
- Source
- psirt@adobe.com
- NVD status
- Analyzed
CVSS 3.1
- Type
- Primary
- Base score
- 9.8
- Impact score
- 5.9
- Exploitability score
- 3.9
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity
- CRITICAL
CVSS 2.0
- Type
- Primary
- Base score
- 10
- Impact score
- 10
- Exploitability score
- 10
- Vector string
- AV:N/AC:L/Au:N/C:C/I:C/A:C
Data from CISA
- Vulnerability name
- Adobe ColdFusion Deserialization Vulnerability
- Exploit added on
- Feb 24, 2025
- Exploit action due
- Mar 17, 2025
- Required action
- Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
- Hype score
- Not currently trending
Actively exploited CVE : CVE-2017-3066, CVE-2024-20953
@transilienceai
8 Mar 2025
21 Impressions
0 Retweets
0 Likes
0 Bookmarks
1 Reply
0 Quotes
#BUGBOARD series is back with #news 2!💡 CISA has added Adobe ColdFusion and Oracle Agile PLM vulnerabilities (CVE-2017-3066 & CVE-2024-20953) to its Known Exploited Vulnerabilities (KEV) catalog due to active exploitation. . Link: https://t.co/bcTqdu69lh #oracle #adobe #secu
@bugbreport
4 Mar 2025
13 Impressions
0 Retweets
2 Likes
0 Bookmarks
1 Reply
0 Quotes
⚠️ Vulnerability Alert: Critical deserialization bugs in Adobe, Oracle software 📅 Timeline: Disclosure: 2017-04-25, Patch: 2024-01-15 📌 Attribution: CISA 🆔cveId: CVE-2017-3066; CVE-2024-20953 📊baseScore: 9.8; 8.8 📏cvssMetrics: cvssSeverity: Critical; High… https://t.co/J
@syedaquib77
25 Feb 2025
27 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
🛑 CISA has warned about two vulnerabilities: CVE-2017-3066 and CVE-2024-20953. Despite patches being available, they're flagged due to continued exploitation risks. 🔗 Read the full article: https://t.co/ooAhN2lHkF
@TheHackersNews
25 Feb 2025
39511 Impressions
33 Retweets
104 Likes
23 Bookmarks
0 Replies
1 Quote
[
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:adobe:coldfusion:10.0:-:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "BB4E08F7-C133-4083-906A-335B9880BA04"
},
{
"criteria": "cpe:2.3:a:adobe:coldfusion:10.0:update1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1C4D259E-56B1-4D53-80A9-52D0687779C4"
},
{
"criteria": "cpe:2.3:a:adobe:coldfusion:10.0:update10:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "191E8CC6-8AD5-40DE-8B5D-1A8BCAEE855D"
},
{
"criteria": "cpe:2.3:a:adobe:coldfusion:10.0:update11:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "FDAC841B-3FE8-46F6-84B4-650D939225F5"
},
{
"criteria": "cpe:2.3:a:adobe:coldfusion:10.0:update12:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "AC034BEB-0ADB-4340-8AFB-30EF67E72815"
},
{
"criteria": "cpe:2.3:a:adobe:coldfusion:10.0:update13:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C8F1ABAB-C4FF-45FD-8C64-23E79F40C043"
},
{
"criteria": "cpe:2.3:a:adobe:coldfusion:10.0:update14:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F56CFA71-3D5E-4A0B-BA4C-9756D0727F8E"
},
{
"criteria": "cpe:2.3:a:adobe:coldfusion:10.0:update15:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "4DB7821D-F4A7-4772-A25B-D925C90478CE"
},
{
"criteria": "cpe:2.3:a:adobe:coldfusion:10.0:update16:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0BB6DF8F-4CA1-448E-8E48-7C2165EC3AE3"
},
{
"criteria": "cpe:2.3:a:adobe:coldfusion:10.0:update17:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "304F3518-82F3-4566-A44D-3FA8D1FEEBCA"
},
{
"criteria": "cpe:2.3:a:adobe:coldfusion:10.0:update18:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B6F8C00C-60CA-4A53-92DF-FB2BF09CF9E3"
},
{
"criteria": "cpe:2.3:a:adobe:coldfusion:10.0:update19:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9B048A36-1E2F-4D0C-AF07-B3D255F170CE"
},
{
"criteria": "cpe:2.3:a:adobe:coldfusion:10.0:update2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "09F8F645-DD28-4159-877E-40B4C8CDA4CC"
},
{
"criteria": "cpe:2.3:a:adobe:coldfusion:10.0:update20:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "79885D33-9360-41D5-9B37-4DC45BDD2439"
},
{
"criteria": "cpe:2.3:a:adobe:coldfusion:10.0:update21:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2BD246BE-C263-46C5-BF2C-E7C4B5C7DD95"
},
{
"criteria": "cpe:2.3:a:adobe:coldfusion:10.0:update22:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "75F104AF-2A38-447B-AB59-09B8F769E787"
},
{
"criteria": "cpe:2.3:a:adobe:coldfusion:10.0:update3:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1B83D6CF-4C45-4B7A-9AFC-9961E1FE0686"
},
{
"criteria": "cpe:2.3:a:adobe:coldfusion:10.0:update4:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F54FF25A-EF5B-4DE0-802C-C9B00A963C21"
},
{
"criteria": "cpe:2.3:a:adobe:coldfusion:10.0:update5:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "705E7F38-9407-4148-835E-5AB994C05F30"
},
{
"criteria": "cpe:2.3:a:adobe:coldfusion:10.0:update6:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "DD7A193C-6CE4-4B80-9897-934BC915627F"
},
{
"criteria": "cpe:2.3:a:adobe:coldfusion:10.0:update7:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "71302041-9BB6-406E-9E77-99AD1594C5C2"
},
{
"criteria": "cpe:2.3:a:adobe:coldfusion:10.0:update8:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "34472770-FFCE-4088-8658-FA0A552BEAA6"
},
{
"criteria": "cpe:2.3:a:adobe:coldfusion:10.0:update9:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "61BC9D5B-1208-4613-BD23-FEA9C404A503"
},
{
"criteria": "cpe:2.3:a:adobe:coldfusion:11.0:-:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E217CE63-07DC-4A88-8877-181F33A21C20"
},
{
"criteria": "cpe:2.3:a:adobe:coldfusion:11.0:update1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "7D4BD25E-6856-40EC-98A8-ACB540992487"
},
{
"criteria": "cpe:2.3:a:adobe:coldfusion:11.0:update10:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "2F0907E8-7BC4-4F5A-894C-B7C5F6BAAEAE"
},
{
"criteria": "cpe:2.3:a:adobe:coldfusion:11.0:update11:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "AFE18FEA-271A-42FE-8C24-19731DEB5444"
},
{
"criteria": "cpe:2.3:a:adobe:coldfusion:11.0:update2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "82F81CF8-1482-4731-AD34-677B8D6B930B"
},
{
"criteria": "cpe:2.3:a:adobe:coldfusion:11.0:update3:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "57BBBE71-BBE0-4129-B997-3F9AF54BFBD8"
},
{
"criteria": "cpe:2.3:a:adobe:coldfusion:11.0:update4:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "8E514D95-9287-4A43-9A44-BD6F8EDC5DA8"
},
{
"criteria": "cpe:2.3:a:adobe:coldfusion:11.0:update5:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "96C50CD1-CE75-4D70-AD65-2DB6027D806A"
},
{
"criteria": "cpe:2.3:a:adobe:coldfusion:11.0:update6:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "AE1B1190-4699-4FB0-AD46-DF0233B5BA90"
},
{
"criteria": "cpe:2.3:a:adobe:coldfusion:11.0:update7:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "827CB550-5078-4FD5-8B1F-616C06912AD9"
},
{
"criteria": "cpe:2.3:a:adobe:coldfusion:11.0:update8:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "31F22450-F26C-4797-9292-66CA444C0D2C"
},
{
"criteria": "cpe:2.3:a:adobe:coldfusion:11.0:update9:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "72450205-B4F4-4B44-9991-F4876D829BBD"
},
{
"criteria": "cpe:2.3:a:adobe:coldfusion:2016:-:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B262F442-FF7F-4CC0-A9C5-FFD0EDB08E38"
},
{
"criteria": "cpe:2.3:a:adobe:coldfusion:2016:update1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "9F3D7C8E-6695-44DF-AC9A-1AE09C46C529"
},
{
"criteria": "cpe:2.3:a:adobe:coldfusion:2016:update2:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "12BAE66C-A745-4661-B5BB-7FC2C169CC82"
},
{
"criteria": "cpe:2.3:a:adobe:coldfusion:2016:update3:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E6EC92F3-1EF8-4820-9CD8-ECEA03D27A7B"
}
],
"operator": "OR"
}
]
}
]