CVE-2023-26359
Description
Adobe ColdFusion versions 2018 Update 15 (and earlier) and 2021 Update 5 (and earlier) are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction.
Summary dbcve.org
Adobe ColdFusion 2018 (up to Update 15) and 2021 (up to Update 5) contain a deserialization vulnerability where untrusted data is processed without proper validation, allowing an unauthenticated attacker to execute arbitrary code in the context of the current user without any user interaction.
Mitigation
Apply the vendor-supplied patches (Update 16 for ColdFusion 2018 and Update 6 for ColdFusion 2021 or later) to remediate the deserialization flaw. If immediate patching is not possible, restrict network access to the ColdFusion administrator interfaces and monitor for Indicators of Compromise.