ZeroHour
The Hacker Newspublished ()ingested @TheHackersNews

CISA Issues Urgent Warning: Adobe ColdFusion Vulnerability Exploited in the Wild

criticalExploit / PoC exploited in the wildimportance 60CVE-2023-26360

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-26360
Unauthenticated RCE via Improper Access Control in Adobe ColdFusion

CVE-2023-26360 is an improper access control flaw (CISA categorizes it as deserialization of untrusted data) in Adobe ColdFusion 2018 (Update 15 and earlier) and ColdFusion 2021 (Update 5 and earlier). It can be triggered over the network with no authentication and no user interaction. A successful attacker achieves arbitrary code execution in the context of the current user, giving them full control of the ColdFusion server. Any organization running the affected ColdFusion versions is exposed, particularly those with instances reachable from the internet; public reporting confirms exploitation in the wild, including a breach of federal agency servers. The flaw was added to CISA's Known Exploited Vulnerabilities Catalog on 2023-03-15, has a public proof-of-concept, and carries a 97.3% EPSS probability of exploitation within 30 days.

Do: Apply Adobe's updates per vendor instructions, upgrading ColdFusion 2018 beyond Update 15 and ColdFusion 2021 beyond Update 5. Because exploitation is unauthenticated and confirmed in the wild (including against a federal agency), prioritize patching internet-facing servers, restrict ColdFusion endpoints to trusted networks in the interim, and hunt for signs of compromise such as web shells, unexpected processes, and suspicious connections (reported activity includes malicious web shell use). Organizations that cannot patch immediately should at minimum limit exposure and monitor for exploitation attempts.

8.697% KEV PoC
  • Adobe ColdFusion 2018 Update 15 and earlier
  • Adobe ColdFusion 2021 Update 5 and earlier
largetens of thousands of internet-exposed ColdFusion servers (public scan data), with many more internal/enterprise deployments
Full article254 words · extracted from thehackernews.com · click to collapse

Ravie LakshmananMar 16, 2023Zero-Day / Vulnerability

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on March 15 added a security vulnerability impacting Adobe ColdFusion to its Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active exploitation.

The critical flaw in question is CVE-2023-26360 (CVSS score: 8.6), which could be exploited by a threat actor to achieve arbitrary code execution.

"Adobe ColdFusion contains an improper access control vulnerability that allows for remote code execution," CISA said.

The vulnerability impacts ColdFusion 2018 (Update 15 and earlier versions) and ColdFusion 2021 (Update 5 and earlier versions). It has been addressed in versions Update 16 and Update 6, respectively, released on March 14, 2023.

It's worth noting that CVE-2023-26360 also affects ColdFusion 2016 and ColdFusion 11 installations, both of which are no longer supported by the software company as they have reached end-of-life (EoL).

While the exact details surrounding the nature of the attacks are unknown, Adobe said in an advisory that it's aware of the flaw being "exploited in the wild in very limited attacks."

Federal Civilian Executive Branch (FCEB) agencies are required to apply the updates by April 5, 2023, to safeguard their networks against potential threats.

Charlie Arehart, a security researcher credited with discovering and reporting the flaw alongside Pete Freitag, described it as a "grave" issue that could result in "arbitrary code execution" and "arbitrary file system read."

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2023/03/cisa-issues-urgent-warning-adobe.html