ZeroHour

CVE-2025-30281

large

Improper Access Control Leading to RCE in Adobe ColdFusion 2021/2023/2025

CVSS 3.1
9.1 critical
EPSS
23%p98
Published
()
Modified
AI analysis

Adobe ColdFusion releases 2025.0, 2023.12, 2021.18 and all earlier versions contain an improper access control flaw (CWE-284) that can result in arbitrary code execution. The flaw is reachable over the network without any user interaction, but the attacker must already hold high privileges on the target (CVSS 9.1 with PR:H), and successful exploitation changes the security scope, letting the attacker break beyond the ColdFusion authorization boundary. A successful attacker can access or modify sensitive data without proper authorization and execute arbitrary code on the server. Any organization running the affected ColdFusion release lines is in scope, though the requirement for high-privilege access reduces practical exposure relative to unauthenticated ColdFusion flaws. It is not yet in CISA KEV and no public proof-of-concept is known, but EPSS assigns a 22.5% probability of exploitation within 30 days (98th percentile), so active exploitation should be treated as a realistic near-term risk.

What to do: Update every ColdFusion 2021, 2023 and 2025 instance to the latest update release per Adobe's advisory, which ships in a batch of 30 fixes (11 critical). Until patched, restrict network access to ColdFusion Administrator and server endpoints, enforce strong and rotated admin credentials, and audit which accounts hold the high-privilege access that exploitation requires. Given the elevated EPSS score, prioritize internet-facing servers and monitor for anomalous admin activity or unexpected process execution on ColdFusion hosts.

Affected
Adobe ColdFusion (2025 release)2025.0 and earlier
Adobe ColdFusion (2023 release)2023.12 and earlier
Adobe ColdFusion (2021 release)2021.18 and earlier
Estimated exposure
largetens of thousands of ColdFusion servers (public internet scans typically show roughly 50,000 exposed instances), with a larger total installed base in… — Internet-wide scan datasets and Shodan-style enumeration of ColdFusion servers on ports such as 80/443/8500 generally show tens of thousands of exposed instances, and ColdFusion's enterprise/government deployment pattern implies a larger…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by an Improper Access Control vulnerability that could result in arbitrary code execution. A high-privileged attacker could leverage this vulnerability to access or modify sensitive data without proper authorization. Exploitation of this issue does not require user interaction, and scope is changed.

Vendors
adobe
Products
coldfusion
Weakness
CWE-284
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

In the news