Executive brief
Adobe ColdFusion is vulnerable to deserialization of untrusted data. An unauthenticated remote attacker can exploit this to execute arbitrary code without user interaction.
Affected products
- Adobe ColdFusion 2018u17 and earlier, 2021u7 and earlier, 2023u1 and earlier
Timeline
- 2023-07-20: disclosed: NVD Published Date
- 2024-01-08: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2024-01-08: advisory: Publication date of the provided advisory summary