Adobe flickt ColdFusion-Schwachstelle mit hohem Ausnutzungsrisiko

Teilen:

Adobe on Monday warned that proof-of-concept (PoC) code exists for a fresh ColdFusion vulnerability.

Tracked as CVE-2024-53961 (CVSS score of 7.4), the security defect is described as a path traversal issue leading to arbitrary file system read if the ‘pmtagent’ package is installed on the ColdFusion server.

“An attacker could exploit this vulnerability to access files or directories that are outside of the restricted directory set by the application. This could lead to the disclosure of sensitive information or the manipulation of system data,” a NIST advisory reads.

Although the flaw has a ‘high severity’ rating based on its CVSS score, Adobe considers it critical, marking it as ‘Priority 1’ and warning that it has a high risk of being targeted in attacks.

“Adobe is aware that CVE-2024-53961 has a known proof-of-concept that could cause an arbitrary file system read,” the company warns.

The vulnerability affects ColdFusion 2023 update 11 and earlier and ColdFusion 2021 update 17 and earlier and was resolved with the release of ColdFusion 2023 update 12 and ColdFusion 2021 update 18.

ColdFusion installations should be updated as soon as possible and Adobe also recommends reviewing its lockdown guides for the affected versions and ensuring that the Performance Monitoring Toolset (PMT) server is up and running during the update, if PMT is in use.

Vulnerabilities in Adobe ColdFusion have long been an attractive target for threat actors. Last week, the US cybersecurity agency CISA warned that an improper access control defect in ColdFusion patched in March 2024 has been exploited in the wild. The flaw is tracked as CVE-2024-20767.

Advertisement. Scroll to continue reading.

In December last year, CISA warned that a ColdFusion bug leading to arbitrary code execution had been exploited in attacks targeting servers belonging to a federal civilian executive branch (FCEB) agency. Tracked as CVE-2023-26360, the defect was patched in March 2023, after being exploited in the wild.

Quelle

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
7:38 pm, Mai 17, 2025
Wetter-Symbol 18°C
L: 17° | H: 18°
klarer Himmel
Luftfeuchtigkeit: 54 %
Druck: 1021 mb
Wind: 2 mph ENE
Windböe: 5 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 1%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 5:05 am
Sonnenuntergang: 8:48 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 10:00 pm
Wetter-Symbol
17° | 18°°C 0 mm 0% 4 mph 59 % 1021 mb 0 mm/h
Tomorrow 10:00 pm
Wetter-Symbol
11° | 16°°C 0 mm 0% 9 mph 82 % 1021 mb 0 mm/h
Mo. Mai 19 10:00 pm
Wetter-Symbol
11° | 19°°C 0.2 mm 20% 13 mph 78 % 1022 mb 0 mm/h
Di. Mai 20 10:00 pm
Wetter-Symbol
9° | 21°°C 0.35 mm 35% 9 mph 81 % 1022 mb 0 mm/h
Mi. Mai 21 10:00 pm
Wetter-Symbol
11° | 20°°C 0.09 mm 9% 11 mph 79 % 1020 mb 0 mm/h
Today 10:00 pm
Wetter-Symbol
14° | 17°°C 0 mm 0% 4 mph 59 % 1021 mb 0 mm/h
Tomorrow 1:00 am
Wetter-Symbol
12° | 14°°C 0 mm 0% 4 mph 69 % 1021 mb 0 mm/h
Tomorrow 4:00 am
Wetter-Symbol
11° | 11°°C 0 mm 0% 6 mph 81 % 1021 mb 0 mm/h
Tomorrow 7:00 am
Wetter-Symbol
11° | 11°°C 0 mm 0% 8 mph 82 % 1021 mb 0 mm/h
Tomorrow 10:00 am
Wetter-Symbol
11° | 11°°C 0 mm 0% 8 mph 69 % 1021 mb 0 mm/h
Tomorrow 1:00 pm
Wetter-Symbol
14° | 14°°C 0 mm 0% 7 mph 53 % 1021 mb 0 mm/h
Tomorrow 4:00 pm
Wetter-Symbol
16° | 16°°C 0 mm 0% 9 mph 49 % 1020 mb 0 mm/h
Tomorrow 7:00 pm
Wetter-Symbol
14° | 14°°C 0 mm 0% 8 mph 56 % 1019 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€92,501.64
-0.72%
Ethereum(ETH)
€2,221.30
-4.00%
Fesseln(USDT)
€0.90
-0.01%
XRP(XRP)
€2.10
-2.66%
Solana(SOL)
€149.20
-2.46%
USDC(USDC)
€0.90
0.00%
Dogecoin(DOGE)
€0.193088
-4.75%
Shiba Inu(SHIB)
€0.000013
-4.71%
Pepe(PEPE)
€0.000011
-7.97%
Peanut das Eichhörnchen(PNUT)
€0.269763
-10.66%
Nach oben scrollen