ZeroHour

CVE-2025-43566

large

High-Privileged Path Traversal Enables Arbitrary File Read in Adobe ColdFusion

CVSS 3.1
6.8 medium
EPSS
55%p99
Published
()
Modified
AI analysis

CVE-2025-43566 is an improper limitation of a pathname to a restricted directory (path traversal, CWE-22) in Adobe ColdFusion that allows a crafted pathname to escape restricted directories and read arbitrary files on the server's file system. It is triggered over the network without user interaction, but per the CVSS vector (PR:H) the attacker must already hold high privileges, such as an administrator-level ColdFusion account; the flaw then bypasses ColdFusion's security protections, and the 'scope changed' designation indicates the traversal crosses ColdFusion's security boundary into the underlying system. A successful attacker gains unauthorized read access to arbitrary file system content (high confidentiality impact, no integrity or availability impact), which can expose configuration files, credentials, and other sensitive data. All installations on the ColdFusion 2025, 2023, and 2021 release tracks at or below update levels 2025.1, 2023.13, and 2021.19 respectively are affected. No public proof-of-concept or confirmed in-the-wild exploitation is known and the flaw is not in CISA KEV, but its high EPSS score (55.1% probability of exploitation within 30 days, 99th percentile) makes near-term exploitation plausible.

What to do: Upgrade every affected instance to the first update release beyond 2025.1 on the 2025 track, 2023.13 on the 2023 track, and 2021.19 on the 2021 track, per Adobe's security bulletin for this CVE. Because exploitation requires high-privileged access, audit and harden ColdFusion administrator accounts, enforce strong credentials and MFA, and restrict administrative interfaces to trusted networks. Given the elevated EPSS probability, monitor Adobe advisories and threat feeds closely and patch before any public proof-of-concept or in-the-wild exploitation emerges.

Affected
Adobe ColdFusion2021 release track: 2021.19 and earlier
Adobe ColdFusion2023 release track: 2023.13 and earlier
Adobe ColdFusion2025 release track: 2025.1 and earlier
Estimated exposure
largetens of thousands of internet-exposed ColdFusion servers (public internet-wide scans index roughly 20,000-60,000 instances; total deployments including… — ColdFusion retains a substantial enterprise install base and public internet-wide scans (e.g., Shodan) consistently index tens of thousands of ColdFusion instances, so exposed systems plausibly fall in the 10k-100k band; exploitation…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read. A high-privileged attacker could leverage this vulnerability to bypass security protections and gain unauthorized read access. Exploitation of this issue does not require user interaction and scope is changed.

Vendors
adobe
Products
coldfusion
Weakness
CWE-22
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.