CVE-2018-4939
KEVlargeUnauthenticated Deserialization RCE in Adobe ColdFusion
CISA: Adobe ColdFusion Deserialization of Untrusted Data Vulnerability
Adobe ColdFusion 2016 (Update 5 and earlier) and ColdFusion 11 (Update 13 and earlier) contain a deserialization-of-untrusted-data flaw (CWE-502) that is remotely exploitable without authentication or user interaction. An attacker sends crafted serialized data to a network-accessible ColdFusion component, which the server deserializes without validation. Successful exploitation leads to arbitrary code execution with high impact on confidentiality, integrity, and availability (CVSS 3.1 score 9.8). Any organization running these ColdFusion releases is affected, particularly internet-facing ColdFusion servers, which are common in enterprise and government environments. The flaw is confirmed exploited in the wild (added to CISA KEV on 2021-11-03), carries a 62.1% 30-day exploitation probability (EPSS 99th percentile), and recent NSA reporting highlights it among the flaws actively used by Chinese state-sponsored hackers.
What to do: Upgrade affected ColdFusion 2016 and ColdFusion 11 installations to the latest cumulative updates per Adobe's instructions (i.e., newer than Update 5 and Update 13, respectively) and verify no instance still runs a vulnerable build. Because the flaw is unauthenticated and remotely exploitable, prioritize patching internet-facing ColdFusion servers and, as an interim mitigation, restrict external network access to ColdFusion services and administrative components. Given the KEV listing and reported use by Chinese state-sponsored hackers, also check exposed ColdFusion servers for signs of exploitation.
| Adobe ColdFusion 2016 | Update 5 and earlier |
| Adobe ColdFusion 11 | Update 13 and earlier |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Adobe ColdFusion Update 5 and earlier versions, ColdFusion 11 Update 13 and earlier versions have an exploitable Deserialization of Untrusted Data vulnerability. Successful exploitation could lead to arbitrary code execution.
- Affected
- Adobe ColdFusion
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- adobe
- Products
- coldfusion
- Weakness
- CWE-502
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H