Junglewise Threat Intelligence

CVE-2023-29300: Adobe ColdFusion Deserialization of Untrusted Data Vulnerability

CVE-2023-29300 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2024-01-08

Technologies: Adobe ColdFusion. Vendors: Adobe.

Executive brief

Adobe ColdFusion is vulnerable to deserialization of untrusted data. This flaw allows a remote, unauthenticated attacker to execute arbitrary code on the server without any user interaction.

Affected products

  • Adobe ColdFusion 2018u16 and earlier, 2021u6 and earlier, 2023.0.0.330468 and earlier

Timeline

  • 2023-07-20: disclosed: Initial NVD analysis date
  • 2024-01-08: kev added: Added to CISA Known Exploited Vulnerabilities Catalog

Related threats