Executive brief
Adobe ColdFusion is vulnerable to deserialization of untrusted data due to improper access control. This flaw allows an unauthenticated remote attacker to execute arbitrary code in the context of the current user without any interaction.
Affected products
- Adobe ColdFusion 2018 Update 15 and earlier
- Adobe ColdFusion 2021 Update 5 and earlier
Timeline
- 2023-03-15: disclosed
- 2023-03-15: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2023-03-23: advisory: NVD Published Date
- 2023-03-15: patched: Adobe released APSB23-25 advisory and patches
- 2023-03-15: exploited: Reported as exploited in the wild at time of publication