ZeroHour

CVE-2023-29300

KEV ransomwarelarge1

Deserialization of Untrusted Data RCE in Adobe ColdFusion (CVE-2023-29300)

CISA: Adobe ColdFusion Deserialization of Untrusted Data Vulnerability

CVSS 3.1
9.8 critical
EPSS
100%p100
Published
()
KEV added
AI analysis

Adobe ColdFusion contains a deserialization of untrusted data flaw (CWE-502): the application deserializes attacker-supplied, untrusted serialized data without adequate validation, allowing an attacker to trigger code execution on the ColdFusion server. Successful exploitation yields arbitrary code execution in the context of the running ColdFusion server, a foothold that can be leveraged for further compromise and, per CISA, ransomware deployment. Any organization running Adobe ColdFusion is affected, especially internet-facing instances; the CISA data does not enumerate specific affected version ranges, so operators should consult Adobe's advisory for the exact affected and fixed releases. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2024-01-08 with known ransomware use, and EPSS assigns a 100% probability of exploitation within 30 days (100th percentile); no public PoC is known, but the KEV listing and ransomware usage confirm active in-the-wild exploitation.

What to do: Patch every ColdFusion instance with the updates from Adobe's security advisory (APSB23-52), which satisfies the CISA required action to apply vendor mitigations or discontinue use of the product if mitigations are unavailable; prioritize internet-facing servers. If patching must be delayed, restrict network access to the ColdFusion server per vendor guidance and review logs for signs of exploitation or ransomware activity.

Affected
Adobe ColdFusion
Estimated exposure
large~10,000-50,000 internet-exposed ColdFusion servers (tens of thousands), plus additional internal deployments — Public internet scan surveys have historically surfaced on the order of tens of thousands of ColdFusion servers exposed to the internet, and the total installed base is larger because many deployments run behind the firewall, placing the…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Adobe ColdFusion versions 2018u16 (and earlier), 2021u6 (and earlier) and 2023.0.0.330468 (and earlier) are affected by a Deserialization of Untrusted Data vulnerability that could result in Arbitrary code execution. Exploitation of this issue does not require user interaction.

CISA Known Exploited Vulnerability
Affected
Adobe ColdFusion
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Known
Vendors
adobe
Products
coldfusion
Weakness
CWE-502
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news