CVE-2017-3066 is a critical Java deserialization vulnerability in the Apache BlazeDS library affecting Adobe ColdFusion versions 2016 Update 3 and earlier, 11 Update 11 and earlier, and 10 Update 22 and earlier. This flaw allows an unauthenticated attacker to achieve arbitrary code execution remotely with low attack complexity. The vulnerability has a CVSS score of 9.8 (Critical) and is actively exploited in the wild, as confirmed by its inclusion in CISA's KEV catalog. Exploit code is publicly available, and it has garnered significant community discussion and media coverage, indicating widespread awareness and concern.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
10.0CPE matchmatch criteria | cpe:2.3:a:adobe:coldfusion:10.0:-:*:*:*:*:*:* | ||
10.0CPE matchmatch criteria | cpe:2.3:a:adobe:coldfusion:10.0:update1:*:*:*:*:*:* | ||
10.0CPE matchmatch criteria | cpe:2.3:a:adobe:coldfusion:10.0:update10:*:*:*:*:*:* | ||
10.0CPE matchmatch criteria | cpe:2.3:a:adobe:coldfusion:10.0:update11:*:*:*:*:*:* | ||
10.0CPE matchmatch criteria | cpe:2.3:a:adobe:coldfusion:10.0:update12:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.