CVE-2025-61810
BaseFortify
Publication date: 2025-12-10
Last updated on: 2025-12-12
Assigner: Adobe Systems Incorporated
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| adobe | coldfusion | 2021.22 |
| adobe | coldfusion | 2023.16 |
| adobe | coldfusion | 2025.4 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-502 | The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability is a Deserialization of Untrusted Data issue in certain versions of ColdFusion. It occurs when the application processes maliciously crafted serialized data provided by an attacker, which can lead to arbitrary code execution within the context of the current user. Exploitation requires user interaction and involves a change in scope.
How can this vulnerability impact me? :
If exploited, this vulnerability can allow a high privileged attacker to execute arbitrary code on the affected system, potentially leading to full compromise of the application and its data. This can result in data loss, unauthorized access, and disruption of services.