Adobe Campaign Classic (versions prior to 7.4.3 build 9398)
Adobe Campaign Classic is enterprise marketing software used by large organisations to manage and automate mass email, SMS, and direct mail campaigns.
Root Cause
The software fails to correctly verify whether a requesting party is authorised before executing privileged operations. When authorisation checks are absent or bypassed, the server treats an attacker's request with the same trust as a legitimate administrator's. Adobe has not disclosed the precise technical mechanism publicly.
Attack Vector
An attacker sends a crafted request to an affected Campaign Classic server without needing a valid account or any victim to click anything. The server, lacking proper authorisation checks, processes the request and executes attacker-supplied code under the permissions of whatever account the server runs as.
Detection Notes
Review server-side logs for unexpected process spawning from the Campaign Classic service account. Look for outbound connections to unfamiliar hosts originating from the application process. Flag any authentication or permission-related errors that appear in bulk or in unusual sequences.
Recommended Actions
- Upgrade Adobe Campaign Classic to v7.4.3 build 9398 on all Windows and Linux deployments immediately.
- Restrict network access to Campaign Classic servers to known, trusted IP ranges.
- Monitor application logs for anomalous process execution or unexpected outbound traffic.

