ZeroHour

CVE-2024-41874

large

Unauthenticated deserialization RCE in Adobe ColdFusion

CVSS 3.1
9.8 critical
EPSS
30%p98
Published
()
Modified
AI analysis

Adobe ColdFusion versions 2023.9 and 2021.15 and earlier contain a deserialization of untrusted data flaw (CWE-502) that allows arbitrary code execution in the context of the current user. The flaw is triggerable over the network with crafted serialized input supplied to the application; exploitation requires no privileges and no user interaction, per the CVSS vector (AV:N/PR:N/UI:N). A successful attacker gains code execution on the ColdFusion server, with high impact to confidentiality, integrity, and availability. Any organization running an affected ColdFusion release is exposed, with internet-facing ColdFusion servers at greatest risk. As of the current data, the issue is not in CISA's KEV catalog and no public proof-of-concept is known, but the 30.3% EPSS score (98th percentile) indicates an elevated likelihood of exploitation within 30 days.

What to do: Patch promptly with Adobe's ColdFusion security updates (APSB24-41): affected servers must be updated beyond release 2023.9 on the 2023 line and beyond release 2021.15 on the 2021 line. Until patched, restrict internet exposure of ColdFusion servers and limit access to ColdFusion administrative endpoints. Review web/application logs for anomalous serialized input or unexpected code execution, and re-scan your environment to confirm all ColdFusion instances are at a fixed release.

Affected
adobe coldfusionColdFusion 2023, update 2023.9 and earlier
adobe coldfusionColdFusion 2021, update 2021.15 and earlier
Estimated exposure
largetens of thousands of internet-exposed ColdFusion servers (public internet scans show roughly 30,000+ instances) — Internet-wide scanning services such as Shodan have historically indexed on the order of 30,000+ Adobe ColdFusion servers reachable on the public internet, and additional internal/intranet deployments that are not exposed to the internet…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

ColdFusion versions 2023.9, 2021.15 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability by providing crafted input to the application, which when deserialized, leads to execution of malicious code. Exploitation of this issue does not require user interaction.

Vendors
adobe
Products
coldfusion
Weakness
CWE-502
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.