ZeroHour
Security Affairspublished ()ingested @securityaffairs

Adobe is aware that ColdFusion bug CVE-2024

criticalExploit / PoC exploited in the wildimportance 60CVE-2024-53961CVE-2024-20767

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-20767
Improper Access Control in Adobe ColdFusion Enables Arbitrary File Read

Adobe ColdFusion contains an improper access control flaw (CWE-284) that allows an unauthenticated attacker to read arbitrary files on the server's file system; per Adobe's advisory, an attacker could also access or modify restricted files. Exploitation occurs over the network with no authentication and no user interaction, but it requires the ColdFusion Administrator panel to be exposed to the internet. A successful attacker can retrieve restricted files, potentially exposing sensitive configuration and credential material stored on the server. Organizations running ColdFusion 2023.6 or earlier on the 2023 release, or 2021.12 or earlier on the 2021 release, with the admin panel reachable from the internet are affected. The flaw is confirmed exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2024-12-16, thousands of exploit attempts were observed during the Christmas holiday, and EPSS assigns a 98.5% probability of exploitation within 30 days.

Do: Upgrade ColdFusion 2023 to a version later than 2023.6 and ColdFusion 2021 to a version later than 2021.12 per Adobe's advisory and CISA's required action. If patching must be deferred, keep the ColdFusion Administrator panel off the public internet by restricting it via firewall, VPN, or IP allowlisting, since internet exposure of the admin panel is required for exploitation. Given the KEV listing (2024-12-16) and thousands of observed exploit attempts over the Christmas holiday, organizations with internet-exposed ColdFusion servers should review logs for exploitation activity and treat prior exposure as a potential compromise.

7.499% KEV
  • Adobe ColdFusion 2023 2023.6 and earlier
  • Adobe ColdFusion 2021 2021.12 and earlier
largeon the order of 10,000-100,000 potentially exposed systems (tens of thousands of internet-reachable ColdFusion servers, of which only those with the…
CVE-2024-53961
ColdFusion versions 2023.11, 2021.17 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability

ColdFusion versions 2023.11, 2021.17 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access files or directories that are outside of the restricted directory set by the application. This could lead to the disclosure of sensitive information or the manipulation of system data. Exploitation of this issue requires the admin panel be exposed to the internet.

NVD description · AI analysis pending
8.114%
  • adobe coldfusion
Full article288 words · extracted from securityaffairs.com · click to collapse

Pierluigi Paganini December 24, 2024

Adobe released out-of-band security updates to address a critical ColdFusion vulnerability, experts warn of a PoC exploit code available for it.

Adobe released out-of-band security updates to address a critical vulnerability, tracked as CVE-2024-53961 (CVSS score 7.4), in ColdFusion. Experts warn of the availability of a proof-of-concept (PoC) exploit code for this vulnerability.

The vulnerability is an improper limitation of a pathname to a restricted directory (‘Path Traversal’) that could lead to arbitrary file system readings.

The flaw impacts Adobe ColdFusion versions 2023 and 2021.

“Adobe has released security updates for ColdFusion versions 2023 and 2021. These updates resolve a critical vulnerability that could lead to arbitrary file system read.” reads the advisory.

“Adobe is aware that CVE-2024-53961 has a known proof-of-concept that could cause an arbitrary file system read,”

The researcher that goes online with the moniker ma4ter reported the vulnerability to the software giant.

The company recommends users update their installations to the newest versions:

ProductUpdated VersionPlatformPriority ratingAvailability
ColdFusion 2023Update 12All1Tech Note
ColdFusion 2021Update 18All1Tech Note

At the time of this writing, it is unclear if the company is aware of attacks in the wild exploiting this vulnerability.

In December, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) added another Adobe ColdFusion issue, tracked as CVE-2024-20767, to its Known Exploited Vulnerabilities (KEV) catalog.

The vulnerability CVE-2024-20767 (CVSS score 7.4) is an Improper Access Control issue in ColdFusion versions 2023.6, 2021.12, and earlier. An attacker can exploit the flaw to gain arbitrary file reads. Exploitation requires an exposed admin panel.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Adobe) 



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/172281/security/adobe-coldfusion-flaw-poc.html