ZeroHour

CVE-2025-43562

large

OS Command Injection in Adobe ColdFusion enables privileged code execution

CVSS 3.1
9.1 critical
EPSS
45%p99
Published
()
Modified
AI analysis

CVE-2025-43562 is an OS command injection flaw (CWE-78) in Adobe ColdFusion that allows arbitrary code execution in the context of the current user. It is triggered over the network without user interaction, but the CVSS vector (PR:H) indicates the attacker must already hold high privileges, which they can then use to bypass security mechanisms and execute commands across the security scope (S:C). Successful exploitation gives the attacker command execution with confidentiality, integrity, and availability impact, effectively letting a highly privileged account escape or bypass ColdFusion's restrictions. All supported ColdFusion tracks are affected: version 2025 up to and including 2025.1, version 2023 up to and including 2023.13, and version 2021 up to and including 2021.19. No public proof-of-concept or confirmed in-the-wild exploitation is known yet, though EPSS assigns a high 45.1% probability of exploitation within 30 days.

What to do: Update every affected ColdFusion installation to the latest patched release on its track (versions beyond 2025.1, 2023.13, and 2021.19 per Adobe's advisory). Until patched, restrict the ColdFusion administrator and other privileged interfaces to trusted networks and review which accounts hold high privileges, since exploitation requires high-privilege access. Given the elevated EPSS score, prioritize internet-facing servers and monitor logs for signs of command execution.

Affected
adobe ColdFusion 20252025.1 and earlier
adobe ColdFusion 20232023.13 and earlier
adobe ColdFusion 20212021.19 and earlier
Estimated exposure
largetens of thousands of internet-exposed ColdFusion servers — Internet-wide scans such as Shodan and Censys have historically shown on the order of tens of thousands of Adobe ColdFusion servers exposed to the internet, with additional unexposed internal deployments raising the total installed base.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result in arbitrary code execution in the context of the current user. A high-privileged attacker could leverage this vulnerability to bypass security mechanisms and execute code. Exploitation of this issue does not require user interaction and scope is changed.

Vendors
adobe
Products
coldfusion
Weakness
CWE-78
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.