Adobe Patches 11 Critical ColdFusion Flaws Amid 30 Total Vulnerabilities Discovered
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-30281 | Improper Access Control Leading to RCE in Adobe ColdFusion 2021/2023/2025 Adobe ColdFusion releases 2025.0, 2023.12, 2021.18 and all earlier versions contain an improper access control flaw (CWE-284) that can result in arbitrary code execution. The flaw is reachable over the network without any user interaction, but the attacker must already hold high privileges on the target (CVSS 9.1 with PR:H), and successful exploitation changes the security scope, letting the attacker break beyond the ColdFusion authorization boundary. A successful attacker can access or modify sensitive data without proper authorization and execute arbitrary code on the server. Any organization running the affected ColdFusion release lines is in scope, though the requirement for high-privilege access reduces practical exposure relative to unauthenticated ColdFusion flaws. It is not yet in CISA KEV and no public proof-of-concept is known, but EPSS assigns a 22.5% probability of exploitation within 30 days (98th percentile), so active exploitation should be treated as a realistic near-term risk. Do: Update every ColdFusion 2021, 2023 and 2025 instance to the latest update release per Adobe's advisory, which ships in a batch of 30 fixes (11 critical). Until patched, restrict network access to ColdFusion Administrator and server endpoints, enforce strong and rotated admin credentials, and audit which accounts hold the high-privilege access that exploitation requires. Given the elevated EPSS score, prioritize internet-facing servers and monitor for anomalous admin activity or unexpected process execution on ColdFusion hosts. | 9.1 group max | 23% |
| largetens of thousands of ColdFusion servers (public internet scans typically show roughly 50,000 exposed instances), with a larger total installed base in… | ||
| CVE-2025-27182 +1 in the same advisory: …27183 | After Effects versions 25.1, 24.6.4 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the contex After Effects versions 25.1, 24.6.4 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. NVD description · AI analysis pending | 7.8 | <1% |
| — | ||
| CVE-2025-27193 | Bridge versions 14.1.5, 15.0.2 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the conte Bridge versions 14.1.5, 15.0.2 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. NVD description · AI analysis pending | 7.8 | <1% |
| — | ||
| CVE-2025-27195 +1 in the same advisory: …27194 | Media Encoder versions 25.1, 24.6.4 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the Media Encoder versions 25.1, 24.6.4 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. NVD description · AI analysis pending | 7.8 | <1% |
| — | ||
| CVE-2025-27196 | Premiere Pro versions 25.1, 24.6.4 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the c Premiere Pro versions 25.1, 24.6.4 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. NVD description · AI analysis pending | 7.8 | <1% |
| — | ||
| CVE-2025-27198 | Photoshop Desktop versions 25.12.1, 26.4.1 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution Photoshop Desktop versions 25.12.1, 26.4.1 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. NVD description · AI analysis pending | 7.8 | <1% |
| — | ||
| CVE-2025-27199 | Animate versions 24.0.7, 23.0.10 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the con Animate versions 24.0.7, 23.0.10 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. NVD description · AI analysis pending | 7.8 | <1% |
| — | ||
| CVE-2025-30295 | Adobe Framemaker versions 2020.8, 2022.6 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in Adobe Framemaker versions 2020.8, 2022.6 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. NVD description · AI analysis pending | 7.8 | <1% |
| — |
Full article403 words · extracted from thehackernews.com · click to collapse
Ravie LakshmananApr 09, 2025Software Security / Vulnerability
Adobe has released security updates to fix a fresh set of security flaws, including multiple critical-severity bugs in ColdFusion versions 2025, 2023 and 2021 that could result in arbitrary file read and code execution.
Of the 30 flaws in the product, 11 are rated Critical in severity -
- CVE-2025-24446 (CVSS score: 9.1) - An improper input validation vulnerability that could result in an arbitrary file system read
- CVE-2025-24447 (CVSS score: 9.1) - A deserialization of untrusted data vulnerability that could result in arbitrary code execution
- CVE-2025-30281 (CVSS score: 9.1) - An improper access control vulnerability that could result in an arbitrary file system read
- CVE-2025-30282 (CVSS score: 9.1) - An improper authentication vulnerability that could result in arbitrary code execution
- CVE-2025-30284 (CVSS score: 8.0) - A deserialization of untrusted data vulnerability that could result in arbitrary code execution
- CVE-2025-30285 (CVSS score: 8.0) - A deserialization of untrusted data vulnerability that could result in arbitrary code execution
- CVE-2025-30286 (CVSS score: 8.0) - An operating system command injection vulnerability that could result in arbitrary code execution
- CVE-2025-30287 (CVSS score: 8.1) - An improper authentication vulnerability that could result in arbitrary code execution
- CVE-2025-30288 (CVSS score: 7.8) - An improper access control vulnerability that could result in a security feature bypass
- CVE-2025-30289 (CVSS score: 7.5) - An operating system command injection vulnerability that could result in arbitrary code execution
- CVE-2025-30290 (CVSS score: 8.7) - A path traversal vulnerability that could result in a security feature bypass
"These updates resolve critical and important vulnerabilities that could lead to arbitrary file system read, arbitrary code execution and security feature bypass," Adobe said in an advisory.
The vulnerabilities have been resolved in the below versions -
- ColdFusion 2021 Update 19
- ColdFusion 2023 Update 13, and
- ColdFusion 2025 Update 1
Fixes have also been released to address several out-of-bounds write and heap-based buffer overflow bugs in After Effects (CVE-2025-27182, CVE-2025-27183), Media Encoder (CVE-2025-27194, CVE-2025-27195), Bridge (CVE-2025-27193), Premiere Pro (CVE-2025-27196), Photoshop (CVE-2025-27198), Animate (CVE-2025-27199), and FrameMaker (CVE-2025-30304, CVE-2025-30297, CVE-2025-30295) that could lead to arbitrary code execution.
Adobe also noted that it's not aware of any exploits for any of the aforementioned shortcomings. That said, it's essential that users update their installations to the latest version to safeguard against potential threats.
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2025/04/adobe-patches-11-critical-coldfusion.html