CVE-2025-43562
largeOS Command Injection in Adobe ColdFusion enables privileged code execution
CVE-2025-43562 is an OS command injection flaw (CWE-78) in Adobe ColdFusion that allows arbitrary code execution in the context of the current user. It is triggered over the network without user interaction, but the CVSS vector (PR:H) indicates the attacker must already hold high privileges, which they can then use to bypass security mechanisms and execute commands across the security scope (S:C). Successful exploitation gives the attacker command execution with confidentiality, integrity, and availability impact, effectively letting a highly privileged account escape or bypass ColdFusion's restrictions. All supported ColdFusion tracks are affected: version 2025 up to and including 2025.1, version 2023 up to and including 2023.13, and version 2021 up to and including 2021.19. No public proof-of-concept or confirmed in-the-wild exploitation is known yet, though EPSS assigns a high 45.1% probability of exploitation within 30 days.
What to do: Update every affected ColdFusion installation to the latest patched release on its track (versions beyond 2025.1, 2023.13, and 2021.19 per Adobe's advisory). Until patched, restrict the ColdFusion administrator and other privileged interfaces to trusted networks and review which accounts hold high privileges, since exploitation requires high-privilege access. Given the elevated EPSS score, prioritize internet-facing servers and monitor logs for signs of command execution.
| adobe ColdFusion 2025 | 2025.1 and earlier |
| adobe ColdFusion 2023 | 2023.13 and earlier |
| adobe ColdFusion 2021 | 2021.19 and earlier |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result in arbitrary code execution in the context of the current user. A high-privileged attacker could leverage this vulnerability to bypass security mechanisms and execute code. Exploitation of this issue does not require user interaction and scope is changed.
- Vendors
- adobe
- Products
- coldfusion
- Weakness
- CWE-78
- Vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.