ZeroHour
Ars Technica · Securitypublished ()ingested 1

Exploited 0-days, an incomplete fix, and a botched disclosure: Infosec snafu reigns

criticalPolicy & legal exploited in the wildimportance 60CVE-2023-29300

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-29300
Deserialization of Untrusted Data RCE in Adobe ColdFusion (CVE-2023-29300)

Adobe ColdFusion contains a deserialization of untrusted data flaw (CWE-502): the application deserializes attacker-supplied, untrusted serialized data without adequate validation, allowing an attacker to trigger code execution on the ColdFusion server. Successful exploitation yields arbitrary code execution in the context of the running ColdFusion server, a foothold that can be leveraged for further compromise and, per CISA, ransomware deployment. Any organization running Adobe ColdFusion is affected, especially internet-facing instances; the CISA data does not enumerate specific affected version ranges, so operators should consult Adobe's advisory for the exact affected and fixed releases. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2024-01-08 with known ransomware use, and EPSS assigns a 100% probability of exploitation within 30 days (100th percentile); no public PoC is known, but the KEV listing and ransomware usage confirm active in-the-wild exploitation.

Do: Patch every ColdFusion instance with the updates from Adobe's security advisory (APSB23-52), which satisfies the CISA required action to apply vendor mitigations or discontinue use of the product if mitigations are unavailable; prioritize internet-facing servers. If patching must be delayed, restrict network access to the ColdFusion server per vendor guidance and review logs for signs of exploitation or ransomware activity.

9.8100% KEV ransomware
  • Adobe ColdFusion
large~10,000-50,000 internet-exposed ColdFusion servers (tens of thousands), plus additional internal deployments
Full article306 words · extracted from arstechnica.com · click to collapse

In fact, Adobe had not patched the mislabeled vulnerability, which Project Discovery warned posed a “significant threat, allowing malicious actors to execute arbitrary code on vulnerable ColdFusion 2018, 2021, and 2023 installations without the need for prior authentication.” In effect, the security company had inadvertently dropped a critical zero-day on users already contending with the threat posed by the incomplete patch. Project Discovery promptly removed the disclosure post, and two days later, Adobe patched the vulnerability.

But by then, the moves were too late. Rapid7 said the two vulnerabilities—one that wasn’t properly patched and the other that was mistakenly disclosed two days prior to Adobe releasing a fix—are still being exploited on vulnerable servers. Fellow security firm Qualys further reported that in addition to those two vulnerabilities, attackers are also exploiting CVE-2023-29300, a separate ColdFusion vulnerability Adobe fixed last week. It also carries a 9.8 severity rating.

Both Rapid7 and Qualys said that the ColdFusion vulnerabilities are being exploited to install webshells, which are browser-like windows that allow people to remotely issue commands and execute code on a server. Neither security company provided further details about the attacks or the parties behind them.

People trying to assess the potential damage from failing to timely patch the vulnerabilities in Citrix’s NetScaler products or Adobe’s ColdFusion need look no further than the fallout from the recent mass exploitations of similarly critical vulnerabilities in two other widely used enterprise applications. As of Monday, critical flaws in the MOVEit file transfer software had led to the breach of 357 separate organizations, according to Emsisoft security analyst Brett Callow. Casualties include multiple government agencies.

Exploits of vulnerabilities in GoAnywhere, a different file-transfer app for enterprises, has claimed more than 100 organizations. Patches for both vulnerabilities have since been widely installed. Organizations relying on either ColdFusion or NetScaler should follow suit.

Text extracted automatically; images, tables and formatting may be missing. Original: https://arstechnica.com/security/2023/07/vulnerabilities-in-adobe-coldfusion-and-citrix-netscaler-are-under-active-exploitation/