ZeroHour

CVE-2013-0629

KEVlarge

Actively Exploited Directory Traversal in Adobe ColdFusion

CISA: Adobe ColdFusion Directory Traversal Vulnerability

CVSS
EPSS
66%p99
Published
KEV added
AI analysis

Adobe ColdFusion contains a directory traversal vulnerability (CWE-264) that permits an unauthorized user to access restricted directories outside the paths the application is meant to expose. It is triggered when an attacker submits crafted input containing directory traversal sequences to a ColdFusion server, bypassing the access controls that normally confine requests to allowed directories. Successful exploitation can allow an attacker to read files in restricted directories, potentially including configuration files containing credentials, enabling further compromise of the host. Any organization running Adobe ColdFusion servers is affected, with the highest risk on servers exposed to the internet. The flaw is confirmed exploited in the wild: it was added to CISA's KEV catalog on 2022-03-07 (federal agencies are required to patch per vendor instructions), EPSS assigns a 65.9% probability of exploitation within 30 days (99th percentile), ransomware association is unknown, and no public PoC is known.

What to do: Inventory all Adobe ColdFusion installations — prioritizing internet-facing servers — and apply the applicable Adobe update per vendor instructions, which is a mandatory federal remediation under the KEV listing. Until patched, restrict network access to ColdFusion servers and monitor access logs for directory-traversal patterns. Because in-the-wild exploitation is confirmed, review affected servers for unauthorized directory/file access and exposed credentials.

Affected
Adobe ColdFusion
Estimated exposure
largetens of thousands of ColdFusion server deployments worldwide, with roughly 10,000–20,000 internet-exposed per public scans — Public internet scans (e.g., Shodan/Censys) have historically shown on the order of 10,000–20,000 internet-exposed Adobe ColdFusion servers, and the total installed base including internal deployments is larger, so the plausibly affected…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Adobe Coldfusion contains a directory traversal vulnerability, which could permit an unauthorized user access to restricted directories.

CISA Known Exploited Vulnerability
Affected
Adobe ColdFusion
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
Adobe
Products
ColdFusion
Weakness
CWE-264

In the news