HomeSecurityAdobe: Emergency patch fixes ColdFusion zero-day

Adobe: Emergency patch fixes ColdFusion zero-day

Adobe released an urgent patch to fix a new zero-day exploit of ColdFusion that is being used in attacks.

Adobe: Emergency patch fixes ColdFusion zero-day

Adobe released an urgent updated security release of ColdFusion that fixes critical vulnerabilities, including a fix for a new zero-day vulnerability that is being exploited in attacks.

In the context of today’s update, Adobe fixed three vulnerabilities: a critical remote code execution vulnerability identified as CVE-2023-38204 (score 9.8), a critical improper access control flaw identified as CVE-2023-38205 (score 7.8), and a medium severity improper access control flaw identified as CVE-2023-38206 (score 5.3).

See also: Adobe: Firefly's Generative Fill is coming to Photoshop

Although CVE-2023-38204 is the most critical flaw fixed today, as it is a remote code execution flaw, hackers have not exploited it.

However, Adobe states that the CVE-2023-38205 vulnerability was exploited in limited attacks.

Adobe knows that CVE-2023-38205 has become the subject of exploitation in limited attacks targeting Adobe ColdFusion”, the Adobe security bulletin states.

The vulnerability CVE-2023-38205 is a patch bypass of CVE-2023-29298, a ColdFusion authentication bypass discovered by researcher Stephen Fewer of Rapid7 on July 11.

On July 13, Rapid7 detected attackers chaining exploits of the CVE-2023-29298 flaws and what appeared to be CVE-2023-29300 and CVE-2023-38203 flaws to install webshells on vulnerable ColdFusion servers, thereby gaining remote access to devices.

This Monday, Rapid7 found that the fix for the CVE-2023-29298 vulnerability can be bypassed and disclosed it to Adobe.

Today, Adobe confirmed on BleepingComputer that the fix for CVE-2023-29298 is included in APSB23-47 as CVE-2023-38205 patch.

As this vulnerability is actively exploited in attacks to take control of ColdFusion servers, site administrators are advised to install the update immediately.

Information source: bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS