ZeroHour

CVE-2018-15961

KEV PoC large

Unrestricted File Upload Leading to RCE in Adobe ColdFusion

CISA: Adobe ColdFusion Unrestricted File Upload Vulnerability

CVSS 3.1
9.8 critical
EPSS
100%p100
Published
()
KEV added
AI analysis

Adobe ColdFusion contains an unrestricted file upload flaw (CWE-434) that allows an attacker to upload files of arbitrary type to the server without adequate authentication or validation. The flaw is triggered by sending crafted file-upload requests to vulnerable ColdFusion functionality; uploaded files can then be retrieved and executed (for example, a malicious JSP or webshell), escalating the upload into full remote code execution. Successful exploitation gives an attacker code execution in the context of the ColdFusion server on the host, which is sufficient to deploy webshells or ransomware and move laterally. Any organization running an unpatched ColdFusion server, particularly one exposed to the internet, is affected because the upload path requires no credentials. The flaw is listed in CISA's Known Exploited Vulnerabilities catalog (added 2021-11-03) and carries a maximum EPSS probability of 100%, indicating active exploitation in the wild, although specific ransomware use is listed as unknown.

What to do: Apply the Adobe ColdFusion security update for CVE-2018-15961 (APSB18-33) per vendor instructions. Inspect upload directories and web-accessible ColdFusion folders for unexpected scripts or webshells, and review access logs for suspicious upload activity. Restrict internet exposure of ColdFusion servers; as a KEV entry, patching by the CISA due date is mandatory for federal agencies.

Affected
Adobe ColdFusion
Estimated exposure
largeorder of tens of thousands of internet-exposed ColdFusion servers worldwide — Public internet-wide scan data (Shodan/Censys) routinely indexes on the order of tens of thousands of ColdFusion servers on HTTP/port 8500, and the unauthenticated nature of this bug put all unpatched ones at risk; total install count is…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have an unrestricted file upload vulnerability. Successful exploitation could lead to arbitrary code execution.

CISA Known Exploited Vulnerability
Affected
Adobe ColdFusion
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
adobe
Products
coldfusion
Weakness
CWE-434
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news