ZeroHour

CVE-2025-30285

large

Deserialization RCE in Adobe ColdFusion (2025.0, 2023.12, 2021.18 and earlier)

CVSS 3.1
8.4 high
EPSS
30%p98
Published
()
Modified
AI analysis

CVE-2025-30285 is a deserialization of untrusted data flaw (CWE-502) in Adobe ColdFusion that can result in arbitrary code execution in the context of the current user. The attack vector is the network, but exploitation requires a high-privileged attacker (PR:H) and user interaction (UI:R); once triggered, the attacker bypasses security protections and executes code with scope changed, extending impact beyond the vulnerable component (confidentiality, integrity and availability all rated high). The flaw affects all currently supported ColdFusion release trains listed in the advisory — 2025.0, 2023.12 and 2021.18 and their earlier versions — so nearly any organization running ColdFusion is in scope. As of the dashboard data the issue is not in CISA KEV and no public proof-of-concept is known, but a high EPSS of 29.5% (98th percentile) signals an elevated likelihood of exploitation within 30 days. Adobe shipped the fix as part of a batch addressing 30 ColdFusion vulnerabilities, of which 11 were rated critical.

What to do: Upgrade every ColdFusion 2025, 2023 and 2021 instance to a release newer than 2025.0, 2023.12 and 2021.18 respectively, using Adobe's current security update set that also patches the other critical ColdFusion issues in the same advisory batch. Until patched, restrict network access to ColdFusion servers and limit high-privileged account usage, since exploitation requires an already high-privileged attacker plus user interaction; review deserialization-related endpoints and monitor for exploitation attempts given the high EPSS.

Affected
adobe coldfusion2025.0 and earlier
adobe coldfusion2023.12 and earlier
adobe coldfusion2021.18 and earlier
Estimated exposure
largetens of thousands of deployments (≈10k–30k internet-exposed ColdFusion servers in public scans) — ColdFusion has a substantial enterprise install base and internet-wide scans consistently show on the order of ten thousand to tens of thousands of internet-exposed ColdFusion servers, and because this CVE spans all supported release…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

ColdFusion versions 2023.12, 2021.18, 2025.0 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current user. A high-privileged attacker could leverage this vulnerability to bypass security protections and execute code. Exploitation of this issue requires user interaction and scope is changed.

Vendors
adobe
Products
coldfusion
Weakness
CWE-502
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H

In the news