ZeroHour

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-30281
Improper Access Control Leading to RCE in Adobe ColdFusion 2021/2023/2025

Adobe ColdFusion releases 2025.0, 2023.12, 2021.18 and all earlier versions contain an improper access control flaw (CWE-284) that can result in arbitrary code execution. The flaw is reachable over the network without any user interaction, but the attacker must already hold high privileges on the target (CVSS 9.1 with PR:H), and successful exploitation changes the security scope, letting the attacker break beyond the ColdFusion authorization boundary. A successful attacker can access or modify sensitive data without proper authorization and execute arbitrary code on the server. Any organization running the affected ColdFusion release lines is in scope, though the requirement for high-privilege access reduces practical exposure relative to unauthenticated ColdFusion flaws. It is not yet in CISA KEV and no public proof-of-concept is known, but EPSS assigns a 22.5% probability of exploitation within 30 days (98th percentile), so active exploitation should be treated as a realistic near-term risk.

Do: Update every ColdFusion 2021, 2023 and 2025 instance to the latest update release per Adobe's advisory, which ships in a batch of 30 fixes (11 critical). Until patched, restrict network access to ColdFusion Administrator and server endpoints, enforce strong and rotated admin credentials, and audit which accounts hold the high-privilege access that exploitation requires. Given the elevated EPSS score, prioritize internet-facing servers and monitor for anomalous admin activity or unexpected process execution on ColdFusion hosts.

9.1
group max
23%
  • Adobe ColdFusion (2025 release) 2025.0 and earlier
  • Adobe ColdFusion (2023 release) 2023.12 and earlier
  • Adobe ColdFusion (2021 release) 2021.18 and earlier
largetens of thousands of ColdFusion servers (public internet scans typically show roughly 50,000 exposed instances), with a larger total installed base in…
CVE-2025-27182
+1 in the same advisory: …27183
After Effects versions 25.1, 24.6.4 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the contex

After Effects versions 25.1, 24.6.4 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

NVD description · AI analysis pending
7.8<1%
  • adobe after effects
CVE-2025-27193
Bridge versions 14.1.5, 15.0.2 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the conte

Bridge versions 14.1.5, 15.0.2 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

NVD description · AI analysis pending
7.8<1%
  • adobe bridge
CVE-2025-27195
+1 in the same advisory: …27194
Media Encoder versions 25.1, 24.6.4 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the

Media Encoder versions 25.1, 24.6.4 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

NVD description · AI analysis pending
7.8<1%
  • adobe media encoder
CVE-2025-27196
Premiere Pro versions 25.1, 24.6.4 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the c

Premiere Pro versions 25.1, 24.6.4 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

NVD description · AI analysis pending
7.8<1%
  • adobe premiere pro
CVE-2025-27198
Photoshop Desktop versions 25.12.1, 26.4.1 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution

Photoshop Desktop versions 25.12.1, 26.4.1 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

NVD description · AI analysis pending
7.8<1%
  • adobe photoshop
CVE-2025-27199
Animate versions 24.0.7, 23.0.10 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the con

Animate versions 24.0.7, 23.0.10 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

NVD description · AI analysis pending
7.8<1%
  • adobe animate
CVE-2025-30295
+2 in the same advisory: …30297 …30304
Adobe Framemaker versions 2020.8, 2022.6 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in

Adobe Framemaker versions 2020.8, 2022.6 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

NVD description · AI analysis pending
7.8<1%
  • adobe framemaker
Full article403 words · extracted from thehackernews.com · click to collapse

Ravie LakshmananApr 09, 2025Software Security / Vulnerability

Adobe has released security updates to fix a fresh set of security flaws, including multiple critical-severity bugs in ColdFusion versions 2025, 2023 and 2021 that could result in arbitrary file read and code execution.

Of the 30 flaws in the product, 11 are rated Critical in severity -

  • CVE-2025-24446 (CVSS score: 9.1) - An improper input validation vulnerability that could result in an arbitrary file system read
  • CVE-2025-24447 (CVSS score: 9.1) - A deserialization of untrusted data vulnerability that could result in arbitrary code execution
  • CVE-2025-30281 (CVSS score: 9.1) - An improper access control vulnerability that could result in an arbitrary file system read
  • CVE-2025-30282 (CVSS score: 9.1) - An improper authentication vulnerability that could result in arbitrary code execution
  • CVE-2025-30284 (CVSS score: 8.0) - A deserialization of untrusted data vulnerability that could result in arbitrary code execution
  • CVE-2025-30285 (CVSS score: 8.0) - A deserialization of untrusted data vulnerability that could result in arbitrary code execution
  • CVE-2025-30286 (CVSS score: 8.0) - An operating system command injection vulnerability that could result in arbitrary code execution
  • CVE-2025-30287 (CVSS score: 8.1) - An improper authentication vulnerability that could result in arbitrary code execution
  • CVE-2025-30288 (CVSS score: 7.8) - An improper access control vulnerability that could result in a security feature bypass
  • CVE-2025-30289 (CVSS score: 7.5) - An operating system command injection vulnerability that could result in arbitrary code execution
  • CVE-2025-30290 (CVSS score: 8.7) - A path traversal vulnerability that could result in a security feature bypass

"These updates resolve critical and important vulnerabilities that could lead to arbitrary file system read, arbitrary code execution and security feature bypass," Adobe said in an advisory.

The vulnerabilities have been resolved in the below versions -

  • ColdFusion 2021 Update 19
  • ColdFusion 2023 Update 13, and
  • ColdFusion 2025 Update 1

Fixes have also been released to address several out-of-bounds write and heap-based buffer overflow bugs in After Effects (CVE-2025-27182, CVE-2025-27183), Media Encoder (CVE-2025-27194, CVE-2025-27195), Bridge (CVE-2025-27193), Premiere Pro (CVE-2025-27196), Photoshop (CVE-2025-27198), Animate (CVE-2025-27199), and FrameMaker (CVE-2025-30304, CVE-2025-30297, CVE-2025-30295) that could lead to arbitrary code execution.

Adobe also noted that it's not aware of any exploits for any of the aforementioned shortcomings. That said, it's essential that users update their installations to the latest version to safeguard against potential threats.

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2025/04/adobe-patches-11-critical-coldfusion.html