⚠ Actively exploited
Added to CISA KEV on 2025-02-24. Federal agencies required to patch by 2025-03-17. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable..

CVE-2017-3066Deserialization of Untrusted Data in Adobe Coldfusion

Severity
9.8CRITICALNVD
EPSS
93.8%
top 0.13%
CISA KEV
KEV
Added 2025-02-24
Due 2025-03-17
Exploit
Exploited in wild
Active exploitation observed
Affected products
Timeline
PublishedApr 27
KEV addedFeb 24
KEV dueMar 17
Latest updateNov 6
CISA Required Action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Description

Adobe ColdFusion 2016 Update 3 and earlier, ColdFusion 11 update 11 and earlier, ColdFusion 10 Update 22 and earlier have a Java deserialization vulnerability in the Apache BlazeDS library. Successful exploitation could lead to arbitrary code execution.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages1 packages

NVDadobe/coldfusion10.0, 11.0, 2016+2

Patches

🔴Vulnerability Details

3
GHSA
GHSA-7cc9-8vjg-gpp8: Adobe ColdFusion 2016 Update 3 and earlier, ColdFusion 11 update 11 and earlier, ColdFusion 10 Update 22 and earlier have a Java deserialization vulne2022-05-13
CVEList
CVE-2017-3066: Adobe ColdFusion 2016 Update 3 and earlier, ColdFusion 11 update 11 and earlier, ColdFusion 10 Update 22 and earlier have a Java deserialization vulne2017-04-27
VulnCheck
Adobe ColdFusion Deserialization Vulnerability2017

💥Exploits & PoCs

1
Exploit-DB
Adobe Coldfusion 11.0.03.292866 - BlazeDS Java Object Deserialization Remote Code Execution2018-02-07

🔍Detection Rules

2
Suricata
ET WEB_SPECIFIC_APPS Adobe Coldfusion BlazeDS Java Object Deserialization Remote Code Execution (CVE-2017-3066)2025-11-06
Suricata
ET EXPLOIT Adobe Coldfusion BlazeDS Java Object Deserialization Remote Code Execution2018-07-13

📋Vendor Advisories

1
CISA
Adobe ColdFusion Deserialization Vulnerability2025-02-24
CVE-2017-3066 — Deserialization of Untrusted Data | cvebase