Horizon Alert
Summary of the vulnerability and why it matters
Adobe Campaign Classic is affected by a critical code injection vulnerability that could allow a low-privileged attacker to execute arbitrary code remotely without user interaction. This could potentially impact the integrity and availability of systems managing customer data and marketing communications.
- Attackers can run unauthorized code.
- Affects marketing automation and customer data systems.
- Confirm if this critical risk applies to us.
Attack Path
How an attacker could exploit the issue
An attacker with low privileges could leverage this vulnerability by reaching a specific feature within Adobe Campaign Classic that is susceptible to improper control of code generation. This could allow them to execute arbitrary code on the system without requiring any interaction from a user, potentially leading to significant compromise.
- Low-privileged access is sufficient.
- Code injection in a vulnerable feature.
- Arbitrary code execution.
Live Threat
Current exploitation, exposure, and threat context
This vulnerability in Adobe Campaign Classic could allow a low-privileged attacker to execute arbitrary code without user interaction, potentially impacting the confidentiality, integrity, and availability of the system.
- System code and data.
- Via network access.
- Arbitrary code execution.
Operational Fix
Recommended remediation, mitigation, and detection steps
This vulnerability in Adobe Campaign Classic impacts application owners and the platform team responsible for its deployment and maintenance. The immediate first step is to locate all instances of Adobe Campaign Classic, determine their business criticality and external reachability, and identify the specific system owners. Remediation planning should then be risk-based.
- Application owners should lead remediation efforts.
- Verify all Adobe Campaign Classic instances.
- Plan remediation with vendor coordination.