ZeroHour

CVE-2023-38205

KEVlarge

Security Feature Bypass in Adobe ColdFusion Exposes Admin CFM/CFC Endpoints

CISA: Adobe ColdFusion Improper Access Control Vulnerability

CVSS 3.1
7.5 high
EPSS
100%p100
Published
()
KEV added
AI analysis

CVE-2023-38205 is an improper access control flaw (CWE-284) in the administration interface of Adobe ColdFusion that results in a security feature bypass. It can be triggered over the network with no authentication and no user interaction, by sending requests directly to the ColdFusion administrative CFM and CFC endpoints. An attacker who exploits it gains unauthorized access to those admin endpoints, with the CVSS vector indicating high confidentiality impact (no direct integrity or availability impact). Any organization running an unpatched ColdFusion 2018 (Update 18 or earlier), 2021 (Update 8 or earlier), or 2023 (Update 2 or earlier) instance is affected, particularly where the admin endpoints are reachable from untrusted networks. The flaw is being actively exploited: it was added to the CISA KEV catalog on 2023-07-20, EPSS assigns a 99.7% probability of exploitation within 30 days, and related news describes an out-of-band Adobe patch for an actively exploited ColdFusion zero-day plus thousands of observed ColdFusion exploit attempts, with companion flaws (CVE-2023-38203, CVE-2023-29298) used to deploy web shells; no standalone public PoC is known, but the KEV listing confirms in-the-wild use.

What to do: Apply Adobe's July 2023 out-of-band updates by upgrading to ColdFusion 2018 Update 19, 2021 Update 9, and 2023 Update 3, or later. Until patched, restrict network access to the ColdFusion Administrator CFM/CFC endpoints (the standard /CFIDE/administrator area) and review servers for compromise indicators such as web shells, given the companion ColdFusion flaws were exploited to deploy web shells. As a CISA KEV entry, federal and other KEV-bound operators must apply the vendor mitigations or discontinue use of the product if mitigations are unavailable.

Affected
Adobe ColdFusion2018 Update 18 and earlier
Adobe ColdFusion2021 Update 8 and earlier
Adobe ColdFusion2023 Update 2 and earlier
Estimated exposure
largetens of thousands of internet-exposed ColdFusion servers (roughly 30,000-50,000), plus a larger installed base behind firewalls — ColdFusion is typically deployed as a self-hosted enterprise application server, and public internet scan counts of exposed ColdFusion servers have consistently been in the tens of thousands, though the total installed base including…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Adobe ColdFusion versions 2018u18 (and earlier), 2021u8 (and earlier) and 2023u2 (and earlier) are affected by an Improper Access Control vulnerability that could result in a Security feature bypass. An attacker could leverage this vulnerability to access the administration CFM and CFC endpoints. Exploitation of this issue does not require user interaction.

CISA Known Exploited Vulnerability
Affected
Adobe ColdFusion
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
adobe
Products
coldfusion
Weakness
CWE-284
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news