CVE-2024-41874
largeUnauthenticated deserialization RCE in Adobe ColdFusion
Adobe ColdFusion versions 2023.9 and 2021.15 and earlier contain a deserialization of untrusted data flaw (CWE-502) that allows arbitrary code execution in the context of the current user. The flaw is triggerable over the network with crafted serialized input supplied to the application; exploitation requires no privileges and no user interaction, per the CVSS vector (AV:N/PR:N/UI:N). A successful attacker gains code execution on the ColdFusion server, with high impact to confidentiality, integrity, and availability. Any organization running an affected ColdFusion release is exposed, with internet-facing ColdFusion servers at greatest risk. As of the current data, the issue is not in CISA's KEV catalog and no public proof-of-concept is known, but the 30.3% EPSS score (98th percentile) indicates an elevated likelihood of exploitation within 30 days.
What to do: Patch promptly with Adobe's ColdFusion security updates (APSB24-41): affected servers must be updated beyond release 2023.9 on the 2023 line and beyond release 2021.15 on the 2021 line. Until patched, restrict internet exposure of ColdFusion servers and limit access to ColdFusion administrative endpoints. Review web/application logs for anomalous serialized input or unexpected code execution, and re-scan your environment to confirm all ColdFusion instances are at a fixed release.
| adobe coldfusion | ColdFusion 2023, update 2023.9 and earlier |
| adobe coldfusion | ColdFusion 2021, update 2021.15 and earlier |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
ColdFusion versions 2023.9, 2021.15 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability by providing crafted input to the application, which when deserialized, leads to execution of malicious code. Exploitation of this issue does not require user interaction.
- Vendors
- adobe
- Products
- coldfusion
- Weakness
- CWE-502
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.