CVE-2023-38203
Adobe ColdFusion Deserialization of Untrusted Data Vulnerability
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 29 January 2024). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
Adobe ColdFusion versions 2018u17 (and earlier), 2021u7 (and earlier) and 2023u1 (and earlier) are affected by a Deserialization of Untrusted Data vulnerability that could result in Arbitrary code execution. Exploitation of this issue does not require user interaction.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 97.07% probability · 100th percentile
- CISA KEV
- Listed 8 January 2024 · due 29 January 2024 · used in ransomware campaigns
- Weakness
- CWE-502
- Affected
- adobe/coldfusion
- Source
- psirt@adobe.com
CISA notes
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. https://helpx.adobe.com/security/products/coldfusion/apsb23-41.html ; https://nvd.nist.gov/vuln/detail/CVE-2023-38203
References
- https://helpx.adobe.com/security/products/coldfusion/apsb23-41.htmlPatch, Vendor Advisory
- https://helpx.adobe.com/security/products/coldfusion/apsb23-41.htmlPatch, Vendor Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-38203Third Party Advisory, US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.