ZeroHour

CVE-2018-4939

KEVlarge

Unauthenticated Deserialization RCE in Adobe ColdFusion

CISA: Adobe ColdFusion Deserialization of Untrusted Data Vulnerability

CVSS 3.1
9.8 critical
EPSS
62%p99
Published
()
KEV added
AI analysis

Adobe ColdFusion 2016 (Update 5 and earlier) and ColdFusion 11 (Update 13 and earlier) contain a deserialization-of-untrusted-data flaw (CWE-502) that is remotely exploitable without authentication or user interaction. An attacker sends crafted serialized data to a network-accessible ColdFusion component, which the server deserializes without validation. Successful exploitation leads to arbitrary code execution with high impact on confidentiality, integrity, and availability (CVSS 3.1 score 9.8). Any organization running these ColdFusion releases is affected, particularly internet-facing ColdFusion servers, which are common in enterprise and government environments. The flaw is confirmed exploited in the wild (added to CISA KEV on 2021-11-03), carries a 62.1% 30-day exploitation probability (EPSS 99th percentile), and recent NSA reporting highlights it among the flaws actively used by Chinese state-sponsored hackers.

What to do: Upgrade affected ColdFusion 2016 and ColdFusion 11 installations to the latest cumulative updates per Adobe's instructions (i.e., newer than Update 5 and Update 13, respectively) and verify no instance still runs a vulnerable build. Because the flaw is unauthenticated and remotely exploitable, prioritize patching internet-facing ColdFusion servers and, as an interim mitigation, restrict external network access to ColdFusion services and administrative components. Given the KEV listing and reported use by Chinese state-sponsored hackers, also check exposed ColdFusion servers for signs of exploitation.

Affected
Adobe ColdFusion 2016Update 5 and earlier
Adobe ColdFusion 11Update 13 and earlier
Estimated exposure
largetens of thousands of internet-exposed ColdFusion servers (order of magnitude ~10,000-100,000) — ColdFusion is a long-established enterprise Java application server widely used in enterprise and government deployments, and internet-wide scan services such as Shodan have historically shown tens of thousands of publicly reachable…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Adobe ColdFusion Update 5 and earlier versions, ColdFusion 11 Update 13 and earlier versions have an exploitable Deserialization of Untrusted Data vulnerability. Successful exploitation could lead to arbitrary code execution.

CISA Known Exploited Vulnerability
Affected
Adobe ColdFusion
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
adobe
Products
coldfusion
Weakness
CWE-502
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news