Adobe released an urgent patch to fix a new zero-day exploit of ColdFusion that is being used in attacks.

Adobe released an urgent updated security release of ColdFusion that fixes critical vulnerabilities, including a fix for a new zero-day vulnerability that is being exploited in attacks.
In the context of today’s update, Adobe fixed three vulnerabilities: a critical remote code execution vulnerability identified as CVE-2023-38204 (score 9.8), a critical improper access control flaw identified as CVE-2023-38205 (score 7.8), and a medium severity improper access control flaw identified as CVE-2023-38206 (score 5.3).
See also: Adobe: Firefly's Generative Fill is coming to Photoshop
Although CVE-2023-38204 is the most critical flaw fixed today, as it is a remote code execution flaw, hackers have not exploited it.
However, Adobe states that the CVE-2023-38205 vulnerability was exploited in limited attacks.
Adobe knows that CVE-2023-38205 has become the subject of exploitation in limited attacks targeting Adobe ColdFusion”, the Adobe security bulletin states.
The vulnerability CVE-2023-38205 is a patch bypass of CVE-2023-29298, a ColdFusion authentication bypass discovered by researcher Stephen Fewer of Rapid7 on July 11.
On July 13, Rapid7 detected attackers chaining exploits of the CVE-2023-29298 flaws and what appeared to be CVE-2023-29300 and CVE-2023-38203 flaws to install webshells on vulnerable ColdFusion servers, thereby gaining remote access to devices.
This Monday, Rapid7 found that the fix for the CVE-2023-29298 vulnerability can be bypassed and disclosed it to Adobe.
Today, Adobe confirmed on BleepingComputer that the fix for CVE-2023-29298 is included in APSB23-47 as CVE-2023-38205 patch.
As this vulnerability is actively exploited in attacks to take control of ColdFusion servers, site administrators are advised to install the update immediately.
Information source: bleepingcomputer.com
