CVE-2023-29300criticalunder attackransomwareCWE-502

CVE-2023-29300: critical vulnerability in Adobe ColdFusion

Adobe ColdFusion Deserialization of Untrusted Data Arbitrary code execution

Published · Updated

95Vexday Risk Score

Patch now. It under exploitation confirmed by CISA, has a working public exploit and 1 threat group(s) use it.

ssvc Actcvss 9.8epss 100%
from disclosure to weapon
Published on NVDJul 12
CISA KEV+180d
exploitation probability
100%top 1% of all CVEs
observed exploitation
yesCISA + VulnCheck
1 group(s)
Who exploits it — 1

Groups known to exploit this vulnerability (MITRE ATT&CK attribution).

Action required by CISAfederal deadline: 2024-01-29

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

In short

Adobe ColdFusion has a flaw that allows attackers to run malicious code on servers by sending specially crafted data. This happens without needing to trick users and puts all affected servers at serious risk.

Technical detail

CVE-2023-29300 exploits unsafe deserialization of untrusted data in Adobe ColdFusion, enabling remote code execution without user interaction. The vulnerability affects versions 2018u16 and earlier, 2021u6 and earlier, and 2023.0.0.330468 and earlier; attackers can craft malicious serialized objects to achieve arbitrary code execution on the target system.

Summary generated and translated by AI from the official description.

The full analysis of this CVE is available in Portuguese →

Adobe ColdFusion versions 2018u16 (and earlier), 2021u6 (and earlier) and 2023.0.0.330468 (and earlier) are affected by a Deserialization of Untrusted Data vulnerability that could result in Arbitrary code execution. Exploitation of this issue does not require user interaction.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
Adobe · ColdFusion