CVE-2022-35690 is a critical stack-based buffer overflow vulnerability affecting Adobe ColdFusion versions Update 14 (and earlier) and Update 4 (and earlier), allowing for arbitrary code execution. With a CVSS score of 9.8 (Critical), this vulnerability can be exploited remotely without user interaction by sending a crafted network packet, leading to full compromise of the system. Although not yet observed in the KEV catalog, it is on the Hot List, signifying its high potential for exploitation. No public exploit code is currently available, but it has generated significant community discussion regarding unauthenticated Remote Code Execution.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2018CPE matchmatch criteria | cpe:2.3:a:adobe:coldfusion:2018:-:*:*:*:*:*:* | ||
2018CPE matchmatch criteria | cpe:2.3:a:adobe:coldfusion:2018:update1:*:*:*:*:*:* | ||
2018CPE matchmatch criteria | cpe:2.3:a:adobe:coldfusion:2018:update10:*:*:*:*:*:* | ||
2018CPE matchmatch criteria | cpe:2.3:a:adobe:coldfusion:2018:update11:*:*:*:*:*:* | ||
2018CPE matchmatch criteria | cpe:2.3:a:adobe:coldfusion:2018:update12:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.