Threat Advisory

Critical Arbitrary Code Execution Vulnerabilities Patched in Adobe ColdFusion

Threat: Vulnerability
Criticality: High
[subscribe_to_unlock_form]

Summary:

Adobe has released patches for a critical-severity vulnerability, tracked as CVE-2023-38203, in its ColdFusion software. The flaw, present in versions 2023, 2021, and 2018, involves the "deserialization of untrusted data," which allows attackers to supply specially crafted data to execute arbitrary code, potentially leading to a complete system compromise. The company warns that information on exploiting the vulnerability has been published online, indicating a potential risk to systems. This announcement comes shortly after Adobe patched another critical-severity vulnerability, CVE-2023-29300, related to deserialization of untrusted data in ColdFusion. The Zero Day Initiative's Dustin Childs has reported that the first in-the-wild attacks targeting CVE-2023-29300 have been observed. To protect their systems, users are advised to apply the available updates promptly and remain vigilant for potential exploitation attempts.[/subscribe_to_unlock_form]

Summary:

Adobe has released patches for a critical-severity vulnerability, tracked as CVE-2023-38203, in its ColdFusion software. The flaw, present in versions 2023, 2021, and 2018, involves the "deserialization of untrusted data," which allows attackers to supply specially crafted data to execute arbitrary code, potentially leading to a complete system compromise. The company warns that information on exploiting the vulnerability has been published online, indicating a potential risk to systems. This announcement comes shortly after Adobe patched another critical-severity vulnerability, CVE-2023-29300, related to deserialization of untrusted data in ColdFusion. The Zero Day Initiative's Dustin Childs has reported that the first in-the-wild attacks targeting CVE-2023-29300 have been observed. To protect their systems, users are advised to apply the available updates promptly and remain vigilant for potential exploitation attempts.[emaillocker id="1283"]

Recommendations:

We strongly recommend you upgrade the following latest versions of ColdFusion Products.

  • ColdFusion 2023 Update 2
  • ColdFusion 2021 Update 8
  • ColdFusion 2018 Update 18

References:

The following reports contain further technical details:

https://www.securityweek.com/exploitation-of-coldfusion-vulnerability-reported-as-adobe-patches-another-critical-flaw/

[/emaillocker]
crossmenu