ZeroHour

CVE-2024-20767

KEVlarge1

Improper Access Control in Adobe ColdFusion Enables Arbitrary File Read

CISA: Adobe ColdFusion Improper Access Control Vulnerability

CVSS 3.1
7.4 high
EPSS
99%p100
Published
()
KEV added
AI analysis

Adobe ColdFusion contains an improper access control flaw (CWE-284) that allows an unauthenticated attacker to read arbitrary files on the server's file system; per Adobe's advisory, an attacker could also access or modify restricted files. Exploitation occurs over the network with no authentication and no user interaction, but it requires the ColdFusion Administrator panel to be exposed to the internet. A successful attacker can retrieve restricted files, potentially exposing sensitive configuration and credential material stored on the server. Organizations running ColdFusion 2023.6 or earlier on the 2023 release, or 2021.12 or earlier on the 2021 release, with the admin panel reachable from the internet are affected. The flaw is confirmed exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2024-12-16, thousands of exploit attempts were observed during the Christmas holiday, and EPSS assigns a 98.5% probability of exploitation within 30 days.

What to do: Upgrade ColdFusion 2023 to a version later than 2023.6 and ColdFusion 2021 to a version later than 2021.12 per Adobe's advisory and CISA's required action. If patching must be deferred, keep the ColdFusion Administrator panel off the public internet by restricting it via firewall, VPN, or IP allowlisting, since internet exposure of the admin panel is required for exploitation. Given the KEV listing (2024-12-16) and thousands of observed exploit attempts over the Christmas holiday, organizations with internet-exposed ColdFusion servers should review logs for exploitation activity and treat prior exposure as a potential compromise.

Affected
Adobe ColdFusion 20232023.6 and earlier
Adobe ColdFusion 20212021.12 and earlier
Estimated exposure
largeon the order of 10,000-100,000 potentially exposed systems (tens of thousands of internet-reachable ColdFusion servers, of which only those with the… — ColdFusion is a long-established enterprise application server historically showing tens of thousands of hosts in internet-wide scans; the exploitable subset is limited to deployments with the ColdFusion Administrator panel exposed to the…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

ColdFusion versions 2023.6, 2021.12 and earlier are affected by an Improper Access Control vulnerability that could result in arbitrary file system read. An attacker could leverage this vulnerability to access or modify restricted files. Exploitation of this issue does not require user interaction. Exploitation of this issue requires the admin panel be exposed to the internet.

CISA Known Exploited Vulnerability
Affected
Adobe ColdFusion
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
adobe
Products
coldfusion
Weakness
CWE-284
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

In the news