CVE-2023-38203: critical vulnerability in Adobe ColdFusion
Analysis CVE-2023-29300 Bypass: Adobe ColdFusion Pre-Auth RCE
Published · Updated
Patch now. It under exploitation confirmed by CISA, has a working public exploit and 1 threat group(s) use it.
Groups known to exploit this vulnerability (MITRE ATT&CK attribution).
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Adobe ColdFusion has a critical flaw that allows attackers to run malicious code on vulnerable servers without any user interaction. This happens because the software unsafely processes untrusted data, giving attackers a direct path into the system.
ColdFusion 2018u17, 2021u7, and 2023u1 are vulnerable to unsafe deserialization (CWE-502) of untrusted data, enabling unauthenticated remote code execution. The vulnerability requires no user interaction and can be exploited through network-accessible ColdFusion instances to achieve arbitrary code execution with server privileges.
The full analysis of this CVE is available in Portuguese →
In the same product, most dangerous first.