"Adobe Issues Urgent Warning on Exploited ColdFusion RCE Bug"

1 min read
Source: BleepingComputer
"Adobe Issues Urgent Warning on Exploited ColdFusion RCE Bug"
Photo: BleepingComputer
TL;DR Summary

Adobe has issued a warning about a critical pre-authentication remote code execution (RCE) vulnerability, CVE-2023-29300, in ColdFusion that is actively being exploited in attacks. The vulnerability allows unauthenticated visitors to execute commands on vulnerable ColdFusion servers. Although initially not exploited in the wild, Adobe has confirmed limited attacks. The details of the exploitation are unknown, but a proof-of-concept exploit has been published. Adobe recommends upgrading to the latest version of ColdFusion to patch the vulnerability, while researchers warn that it can be combined with another vulnerability, CVE-2023-29298, to bypass lockdown mode. Adobe has not yet responded to inquiries about the active exploitation.

Share this article

Reading Insights

Total Reads

0

Unique Readers

0

Time Saved

1 min

vs 2 min read

Condensed

74%

386102 words

Want the full story? Read the original article

Read on BleepingComputer