LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2017-3066: Adobe ColdFusion Deserialization Vulnerability

RBRecent Breaches Vulnerability Intelligence·Feb 24, 2025
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Mar 17, 2025
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2017-3066 to its Known Exploited Vulnerabilities catalog on Feb 24, 2025, with a federal patch deadline of Mar 17, 2025 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Adobe ColdFusion contains a deserialization vulnerability in the Apache BlazeDS library that allows for arbitrary code execution.

CVE-2017-3066 is a deserialization vulnerability affecting Adobe ColdFusion. It involves the Apache BlazeDS library and can allow an attacker to achieve arbitrary code execution on a vulnerable system.

This matters for IT and security teams because successful exploitation can give an attacker control over the ColdFusion process and the host it runs on, enabling further compromise of applications, data, or connected systems. Confirm all specifics against the vendor advisory before acting.

How it works

The weakness is CWE-502: deserialization of untrusted data. In this case, Adobe ColdFusion contains a deserialization vulnerability in the Apache BlazeDS library that allows for arbitrary code execution.

An attacker abuses the flaw by supplying crafted serialized input that the application processes without adequate validation. When the library deserializes that input, it can lead to execution of attacker-controlled code in the context of the ColdFusion process. Exact exploit mechanics, required endpoints, and preconditions are not detailed here and must be confirmed against the vendor advisory. In general for this class of issue, exposure of the deserialization functionality (for example via network-accessible services) increases risk.

Am I affected? How to find it in your systems

Adobe ColdFusion is commonly used to host and run web applications and related services, often on Windows or Linux application servers in enterprise environments. Inventory efforts should focus on locating ColdFusion installations rather than assuming presence based on other Adobe products.

For signs of exploitation, examine application and system logs for unusual deserialization activity, unexpected process creation or command execution originating from the ColdFusion process, anomalous outbound connections, or EDR/telemetry alerts involving the ColdFusion binary. Specific indicators of compromise are not provided here; treat any unexplained code execution or persistence on ColdFusion hosts as suspicious and investigate.

How to remediate

Patch first. Apply the vendor update that addresses CVE-2017-3066 as named in the official Adobe advisory. Confirm the exact update package, applicability, and installation steps against that advisory. CISA required action is to apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

If you can't patch immediately

Use compensating controls to reduce exposure until the vendor update can be applied.

These steps reduce risk but do not replace the vendor patch. Plan to apply the official update as soon as feasible.

If your data may have been exposed

Actively exploited vulnerabilities can lead to breaches in which data is accessed or exfiltrated. If you have evidence of exploitation, treat the host as compromised, follow your incident response process, and assess what data the ColdFusion application could access. Known ransomware use is not documented for this CVE. Readers can run a free exposure scan of their email to check known breach data.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedAdobe · ColdFusion
WeaknessCWE-502
Added to CISA KEVFeb 24, 2025
Federal patch deadlineMar 17, 2025
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities