ZeroHour
The Hacker Newspublished ()ingested @TheHackersNews

Adobe Rolls Out New Patches for Actively Exploited ColdFusion Vulnerability

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-29298
Unauthenticated Access Control Bypass in Adobe ColdFusion (Actively Exploited)

CVE-2023-29298 is an improper access control flaw (CWE-284) in Adobe ColdFusion that lets a remote, unauthenticated attacker reach ColdFusion's administrative CFM and CFC endpoints, bypassing the access controls meant to protect them. It is triggered directly over the network with no user interaction and no privileges required (CVSS 3.1: 7.5, high confidentiality impact). An attacker gains access to administrative endpoints as a security feature bypass; in practice, Adobe patched this flaw in the same July 2023 out-of-band update as a critical, actively exploited ColdFusion RCE, and it can be used to reach the server's admin surface. All Adobe ColdFusion deployments running 2018 Update 16 (and earlier), 2021 Update 6 (and earlier), or 2023.0.0.330468 (and earlier) are affected. Exploitation is confirmed in the wild: CISA added it to the KEV on 2023-07-20 and EPSS assigns a 99.8% probability of exploitation within 30 days.

Do: Apply Adobe's July 2023 out-of-band ColdFusion updates immediately - upgrade beyond the affected builds (ColdFusion 2018 later than Update 16, e.g. Update 17; 2021 later than Update 6, e.g. Update 7; and the patched 2023 hotfix newer than build 330468) or follow Adobe's advisory instructions, as CISA requires mitigations or discontinuation of use for KEV entries. Until patched, restrict network access to ColdFusion Administrator/CFIDE endpoints from untrusted networks. Because no authentication or interaction is required, review access logs for unauthenticated requests to admin CFM/CFC endpoints and assume possible compromise on unpatched, internet-facing servers.

7.5100% KEV
  • Adobe ColdFusion 2018 Update 16 (2018u16) and earlier
  • Adobe ColdFusion 2021 Update 6 (2021u6) and earlier
  • Adobe ColdFusion 2023.0.0.330468 and earlier
largetens of thousands of internet-exposed ColdFusion servers (roughly 10k-100k instances)
CVE-2023-38203
Unauthenticated Deserialization RCE in Adobe ColdFusion (Actively Exploited)

CVE-2023-38203 is a critical (CVSS 9.8) deserialization-of-untrusted-data flaw (CWE-502) in Adobe ColdFusion that can lead to arbitrary code execution. It is triggered over the network when an affected ColdFusion server processes crafted untrusted serialized data, and exploitation requires no authentication and no user interaction. A successful attacker gains arbitrary code execution with high impact on confidentiality, integrity, and availability of the host. Organizations running ColdFusion 2018 (Update 17 or earlier), ColdFusion 2021 (Update 7 or earlier), or ColdFusion 2023 (Update 1 or earlier) are affected. The flaw is being actively exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2024-01-08 with known ransomware use, EPSS assigns a 96.7% probability of exploitation within 30 days (100th percentile), and Adobe has shipped out-of-band patches in response.

Do: Upgrade all ColdFusion 2018, 2021, and 2023 installations beyond the affected levels (at least past 2018u17, 2021u7, and 2023u1, using the latest update Adobe provides in its advisory). If patching must be delayed, apply the mitigations per Adobe's instructions, restrict or remove internet exposure of ColdFusion servers, and prioritize internet-facing hosts. Because exploitation is confirmed with known ransomware use, review ColdFusion logs and affected hosts for signs of exploitation, webshells, or follow-on malware, and discontinue use of the product if mitigations are unavailable per CISA's required action.

9.897% KEV ransomware
  • adobe coldfusion ColdFusion 2018 releases up to and including Update 17 (2018u17)
  • adobe coldfusion ColdFusion 2021 releases up to and including Update 7 (2021u7)
  • adobe coldfusion ColdFusion 2023 releases up to and including Update 1 (2023u1)
large~tens of thousands of internet-facing ColdFusion servers (order of 10,000-100,000 exposed instances); total install base including internal deployments is…
CVE-2023-38205
+2 in the same advisory: …38204 …38206
Security Feature Bypass in Adobe ColdFusion Exposes Admin CFM/CFC Endpoints

CVE-2023-38205 is an improper access control flaw (CWE-284) in the administration interface of Adobe ColdFusion that results in a security feature bypass. It can be triggered over the network with no authentication and no user interaction, by sending requests directly to the ColdFusion administrative CFM and CFC endpoints. An attacker who exploits it gains unauthorized access to those admin endpoints, with the CVSS vector indicating high confidentiality impact (no direct integrity or availability impact). Any organization running an unpatched ColdFusion 2018 (Update 18 or earlier), 2021 (Update 8 or earlier), or 2023 (Update 2 or earlier) instance is affected, particularly where the admin endpoints are reachable from untrusted networks. The flaw is being actively exploited: it was added to the CISA KEV catalog on 2023-07-20, EPSS assigns a 99.7% probability of exploitation within 30 days, and related news describes an out-of-band Adobe patch for an actively exploited ColdFusion zero-day plus thousands of observed ColdFusion exploit attempts, with companion flaws (CVE-2023-38203, CVE-2023-29298) used to deploy web shells; no standalone public PoC is known, but the KEV listing confirms in-the-wild use.

Do: Apply Adobe's July 2023 out-of-band updates by upgrading to ColdFusion 2018 Update 19, 2021 Update 9, and 2023 Update 3, or later. Until patched, restrict network access to the ColdFusion Administrator CFM/CFC endpoints (the standard /CFIDE/administrator area) and review servers for compromise indicators such as web shells, given the companion ColdFusion flaws were exploited to deploy web shells. As a CISA KEV entry, federal and other KEV-bound operators must apply the vendor mitigations or discontinue use of the product if mitigations are unavailable.

7.5
group max
100% KEV
  • Adobe ColdFusion 2018 Update 18 and earlier
  • Adobe ColdFusion 2021 Update 8 and earlier
  • Adobe ColdFusion 2023 Update 2 and earlier
largetens of thousands of internet-exposed ColdFusion servers (roughly 30,000-50,000), plus a larger installed base behind firewalls
Full article273 words · extracted from thehackernews.com · click to collapse

Ravie LakshmananJul 20, 2023Software Security / Vulnerability

Adobe has released a fresh round of updates to address an incomplete fix for a recently disclosed ColdFusion flaw that has come under active exploitation in the wild.

The critical shortcoming, tracked as CVE-2023-38205 (CVSS score: 7.5), has been described as an instance of improper access control that could result in a security bypass. It impacts the following versions:

  • ColdFusion 2023 (Update 2 and earlier versions)
  • ColdFusion 2021 (Update 8 and earlier versions), and
  • ColdFusion 2018 (Update 18 and earlier versions)

"Adobe is aware that CVE-2023-38205 has been exploited in the wild in limited attacks targeting Adobe ColdFusion," the company said.

The update also addresses two other flaws, including a critical deserialization bug (CVE-2023-38204, CVSS score: 9.8) that could lead to remote code execution and a second improper access control flaw that could also pave the way for a security bypass (CVE-2023-38206, CVSS score: 5.3).

The disclosure arrives days after Rapid7 warned that the fix put in place for CVE-2023-29298 was incomplete and that it could be trivially sidestepped by malicious actors. The cybersecurity firm has confirmed that the new patch completely plugs the security hole.

CVE-2023-29298, an access control bypass vulnerability, has been weaponized in real-world attacks by chaining it with another flaw that's suspected to be CVE-2023-38203 to drop web shells on compromised systems for backdoor access.

Adobe ColdFusion users are highly recommended to update their installations to the latest version to mitigate potential threats.

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2023/07/adobe-rolls-out-new-patches-for.html