ZeroHour

CVE-2010-2861

KEV ransomwarelarge

Directory Traversal in Adobe ColdFusion Administrator Console

CISA: Adobe ColdFusion Directory Traversal Vulnerability

CVSS
EPSS
100%p100
Published
KEV added
AI analysis

CVE-2010-2861 is a directory traversal flaw (CWE-22) in the administrator console of Adobe ColdFusion that allows remote attackers to read arbitrary files on the server. It is triggered by sending crafted path-traversal input to the ColdFusion Administrator web interface, letting the attacker walk outside the intended directory. By reading sensitive files such as the server's configuration and administrator credential files, an attacker can obtain ColdFusion admin credentials and frequently escalate to broader system access. Any organization running an affected Adobe ColdFusion release is exposed, especially servers with the CFIDE administrator interface reachable from the internet. The flaw is actively exploited: it is in CISA's KEV (added 2022-03-25) with known ransomware use (including by the Cring gang), and EPSS puts 30-day exploitation probability at 99.7%.

What to do: Apply the ColdFusion updates per Adobe/vendor instructions as required by CISA, and if patching must wait, restrict or firewall access to the CFIDE administrator console (IP allowlisting or VPN only). Review web logs for path-traversal requests against the administrator console and check hosts for signs of ransomware or unauthorized changes, since exploitation is actively used for ransomware.

Affected
Adobe ColdFusion
Estimated exposure
largetens of thousands of internet-exposed ColdFusion servers — Public internet-wide scans have historically shown tens of thousands of ColdFusion instances exposing the CFIDE administrator interface, and the product's long deployment base in enterprise environments keeps the exposed population large…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A directory traversal vulnerability exists in the administrator console in Adobe ColdFusion which allows remote attackers to read arbitrary files.

CISA Known Exploited Vulnerability
Affected
Adobe ColdFusion
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Known
Vendors
Adobe
Products
ColdFusion
Weakness
CWE-22

In the news