Adobe out-of-band update addresses an actively exploited ColdFusion zero
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2023-29300 +1 in the same advisory: …29298 | Deserialization of Untrusted Data RCE in Adobe ColdFusion (CVE-2023-29300) Adobe ColdFusion contains a deserialization of untrusted data flaw (CWE-502): the application deserializes attacker-supplied, untrusted serialized data without adequate validation, allowing an attacker to trigger code execution on the ColdFusion server. Successful exploitation yields arbitrary code execution in the context of the running ColdFusion server, a foothold that can be leveraged for further compromise and, per CISA, ransomware deployment. Any organization running Adobe ColdFusion is affected, especially internet-facing instances; the CISA data does not enumerate specific affected version ranges, so operators should consult Adobe's advisory for the exact affected and fixed releases. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2024-01-08 with known ransomware use, and EPSS assigns a 100% probability of exploitation within 30 days (100th percentile); no public PoC is known, but the KEV listing and ransomware usage confirm active in-the-wild exploitation. Do: Patch every ColdFusion instance with the updates from Adobe's security advisory (APSB23-52), which satisfies the CISA required action to apply vendor mitigations or discontinue use of the product if mitigations are unavailable; prioritize internet-facing servers. If patching must be delayed, restrict network access to the ColdFusion server per vendor guidance and review logs for signs of exploitation or ransomware activity. | 9.8 group max | 100% | KEV ransomware |
| large~10,000-50,000 internet-exposed ColdFusion servers (tens of thousands), plus additional internal deployments | |
| CVE-2023-38203 | Unauthenticated Deserialization RCE in Adobe ColdFusion (Actively Exploited) CVE-2023-38203 is a critical (CVSS 9.8) deserialization-of-untrusted-data flaw (CWE-502) in Adobe ColdFusion that can lead to arbitrary code execution. It is triggered over the network when an affected ColdFusion server processes crafted untrusted serialized data, and exploitation requires no authentication and no user interaction. A successful attacker gains arbitrary code execution with high impact on confidentiality, integrity, and availability of the host. Organizations running ColdFusion 2018 (Update 17 or earlier), ColdFusion 2021 (Update 7 or earlier), or ColdFusion 2023 (Update 1 or earlier) are affected. The flaw is being actively exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2024-01-08 with known ransomware use, EPSS assigns a 96.7% probability of exploitation within 30 days (100th percentile), and Adobe has shipped out-of-band patches in response. Do: Upgrade all ColdFusion 2018, 2021, and 2023 installations beyond the affected levels (at least past 2018u17, 2021u7, and 2023u1, using the latest update Adobe provides in its advisory). If patching must be delayed, apply the mitigations per Adobe's instructions, restrict or remove internet exposure of ColdFusion servers, and prioritize internet-facing hosts. Because exploitation is confirmed with known ransomware use, review ColdFusion logs and affected hosts for signs of exploitation, webshells, or follow-on malware, and discontinue use of the product if mitigations are unavailable per CISA's required action. | 9.8 | 97% | KEV ransomware |
| large~tens of thousands of internet-facing ColdFusion servers (order of 10,000-100,000 exposed instances); total install base including internal deployments is… | |
| CVE-2023-38205 | Security Feature Bypass in Adobe ColdFusion Exposes Admin CFM/CFC Endpoints CVE-2023-38205 is an improper access control flaw (CWE-284) in the administration interface of Adobe ColdFusion that results in a security feature bypass. It can be triggered over the network with no authentication and no user interaction, by sending requests directly to the ColdFusion administrative CFM and CFC endpoints. An attacker who exploits it gains unauthorized access to those admin endpoints, with the CVSS vector indicating high confidentiality impact (no direct integrity or availability impact). Any organization running an unpatched ColdFusion 2018 (Update 18 or earlier), 2021 (Update 8 or earlier), or 2023 (Update 2 or earlier) instance is affected, particularly where the admin endpoints are reachable from untrusted networks. The flaw is being actively exploited: it was added to the CISA KEV catalog on 2023-07-20, EPSS assigns a 99.7% probability of exploitation within 30 days, and related news describes an out-of-band Adobe patch for an actively exploited ColdFusion zero-day plus thousands of observed ColdFusion exploit attempts, with companion flaws (CVE-2023-38203, CVE-2023-29298) used to deploy web shells; no standalone public PoC is known, but the KEV listing confirms in-the-wild use. Do: Apply Adobe's July 2023 out-of-band updates by upgrading to ColdFusion 2018 Update 19, 2021 Update 9, and 2023 Update 3, or later. Until patched, restrict network access to the ColdFusion Administrator CFM/CFC endpoints (the standard /CFIDE/administrator area) and review servers for compromise indicators such as web shells, given the companion ColdFusion flaws were exploited to deploy web shells. As a CISA KEV entry, federal and other KEV-bound operators must apply the vendor mitigations or discontinue use of the product if mitigations are unavailable. | 7.5 group max | 100% | KEV |
| largetens of thousands of internet-exposed ColdFusion servers (roughly 30,000-50,000), plus a larger installed base behind firewalls |
Full article322 words · extracted from securityaffairs.com · click to collapse

Adobe released an emergency update to address critical vulnerabilities in ColdFusion, including an actively exploited zero-day.
Adobe released an out-of-band update to address critical and moderate vulnerabilities in ColdFusion, including a zero-day flaw that is actively exploited in attacks.
The vulnerabilities could lead to arbitrary code execution and security feature bypass. The impacted ColdFusion versions are 2023, 2021 and 2018.
Below is the list of the issues addressed by the software firm with this out-of-band update:
| Vulnerability Category | Vulnerability Impact | Severity | CVSS base score | CVSS vector | CVE Numbers |
| Deserialization of Untrusted Data (CWE-502) | Arbitrary code execution | Critical | 9.8 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H | CVE-2023-38204 |
| Improper Access Control (CWE-284) | Security feature bypass | Critical | 7.5 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N | CVE-2023-38205 |
| Improper Access Control (CWE-284) | Security feature bypass | Moderate | 5.3 | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N | CVE-2023-38206 |
According to the bulletin, the vulnerability tracked as CVE-2023-38205 has been exploited in the wild in limited attacks targeting ColdFusion. This flaw is an Improper Access Control that could lead to a security feature bypass.
“Adobe has released security updates for ColdFusion versions 2023, 2021 and 2018. These updates resolve critical and moderate vulnerabilities that could lead to arbitrary code execution and security feature bypass.” reads the security bulletin. “Adobe is aware that CVE-2023-38205 has been exploited in the wild in limited attacks targeting Adobe ColdFusion.”
The CVE-2023-38205 vulnerability was discovered by Stephen Fewer from security firm Rapid7.
The CVE-2023-38205 vulnerability is a patch bypass for the fix for the ColdFusion authentication bypass issue tracked as CVE-2023-29298.
Last week, Adobe warned customers of a critical ColdFusion pre-authentication RCE bug, tracked as CVE-2023-29300, which is actively exploited. The issue was part of an exploit chain, that included the CVE-2023-29298 and CVE-2023-38203, which was used to deploy webshells on vulnerable ColdFusion servers.
BllepingComputer confirmed that the fix for CVE-2023-29298 is included in APSB23-47 as the CVE-2023-38205 patch.
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, Adobe)
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/148625/hacking/coldfusion-zero-day.html