CVE-2023-29300: critical vulnerability in Adobe ColdFusion
Adobe ColdFusion Deserialization of Untrusted Data Arbitrary code execution
Published · Updated
Patch now. It under exploitation confirmed by CISA, has a working public exploit and 1 threat group(s) use it.
Groups known to exploit this vulnerability (MITRE ATT&CK attribution).
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Adobe ColdFusion has a flaw that allows attackers to run malicious code on servers by sending specially crafted data. This happens without needing to trick users and puts all affected servers at serious risk.
CVE-2023-29300 exploits unsafe deserialization of untrusted data in Adobe ColdFusion, enabling remote code execution without user interaction. The vulnerability affects versions 2018u16 and earlier, 2021u6 and earlier, and 2023.0.0.330468 and earlier; attackers can craft malicious serialized objects to achieve arbitrary code execution on the target system.
The full analysis of this CVE is available in Portuguese →
In the same product, most dangerous first.