Junglewise Threat Intelligence

CVE-2023-38203: Adobe ColdFusion Deserialization of Untrusted Data Vulnerability

CVE-2023-38203 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2024-01-08

Technologies: Adobe ColdFusion. Vendors: Adobe.

Executive brief

Adobe ColdFusion is vulnerable to deserialization of untrusted data. An unauthenticated remote attacker can exploit this to execute arbitrary code without user interaction.

Affected products

  • Adobe ColdFusion 2018u17 and earlier, 2021u7 and earlier, 2023u1 and earlier

Timeline

  • 2023-07-20: disclosed: NVD Published Date
  • 2024-01-08: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2024-01-08: advisory: Publication date of the provided advisory summary

Related threats