CVE-2025-43566
largeHigh-Privileged Path Traversal Enables Arbitrary File Read in Adobe ColdFusion
CVE-2025-43566 is an improper limitation of a pathname to a restricted directory (path traversal, CWE-22) in Adobe ColdFusion that allows a crafted pathname to escape restricted directories and read arbitrary files on the server's file system. It is triggered over the network without user interaction, but per the CVSS vector (PR:H) the attacker must already hold high privileges, such as an administrator-level ColdFusion account; the flaw then bypasses ColdFusion's security protections, and the 'scope changed' designation indicates the traversal crosses ColdFusion's security boundary into the underlying system. A successful attacker gains unauthorized read access to arbitrary file system content (high confidentiality impact, no integrity or availability impact), which can expose configuration files, credentials, and other sensitive data. All installations on the ColdFusion 2025, 2023, and 2021 release tracks at or below update levels 2025.1, 2023.13, and 2021.19 respectively are affected. No public proof-of-concept or confirmed in-the-wild exploitation is known and the flaw is not in CISA KEV, but its high EPSS score (55.1% probability of exploitation within 30 days, 99th percentile) makes near-term exploitation plausible.
What to do: Upgrade every affected instance to the first update release beyond 2025.1 on the 2025 track, 2023.13 on the 2023 track, and 2021.19 on the 2021 track, per Adobe's security bulletin for this CVE. Because exploitation requires high-privileged access, audit and harden ColdFusion administrator accounts, enforce strong credentials and MFA, and restrict administrative interfaces to trusted networks. Given the elevated EPSS probability, monitor Adobe advisories and threat feeds closely and patch before any public proof-of-concept or in-the-wild exploitation emerges.
| Adobe ColdFusion | 2021 release track: 2021.19 and earlier |
| Adobe ColdFusion | 2023 release track: 2023.13 and earlier |
| Adobe ColdFusion | 2025 release track: 2025.1 and earlier |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read. A high-privileged attacker could leverage this vulnerability to bypass security protections and gain unauthorized read access. Exploitation of this issue does not require user interaction and scope is changed.
- Vendors
- adobe
- Products
- coldfusion
- Weakness
- CWE-22
- Vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.