CVE-2018-15961
KEV PoC largeUnrestricted File Upload Leading to RCE in Adobe ColdFusion
CISA: Adobe ColdFusion Unrestricted File Upload Vulnerability
Adobe ColdFusion contains an unrestricted file upload flaw (CWE-434) that allows an attacker to upload files of arbitrary type to the server without adequate authentication or validation. The flaw is triggered by sending crafted file-upload requests to vulnerable ColdFusion functionality; uploaded files can then be retrieved and executed (for example, a malicious JSP or webshell), escalating the upload into full remote code execution. Successful exploitation gives an attacker code execution in the context of the ColdFusion server on the host, which is sufficient to deploy webshells or ransomware and move laterally. Any organization running an unpatched ColdFusion server, particularly one exposed to the internet, is affected because the upload path requires no credentials. The flaw is listed in CISA's Known Exploited Vulnerabilities catalog (added 2021-11-03) and carries a maximum EPSS probability of 100%, indicating active exploitation in the wild, although specific ransomware use is listed as unknown.
What to do: Apply the Adobe ColdFusion security update for CVE-2018-15961 (APSB18-33) per vendor instructions. Inspect upload directories and web-accessible ColdFusion folders for unexpected scripts or webshells, and review access logs for suspicious upload activity. Restrict internet exposure of ColdFusion servers; as a KEV entry, patching by the CISA due date is mandatory for federal agencies.
| Adobe ColdFusion | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have an unrestricted file upload vulnerability. Successful exploitation could lead to arbitrary code execution.
- Affected
- Adobe ColdFusion
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- adobe
- Products
- coldfusion
- Weakness
- CWE-434
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H