Adobe warns of critical ColdFusion bug with PoC exploit code

Adobe has addressed a serious ColdFusion vulnerability with proof-of-concept (PoC) exploit code by releasing out-of-band security upgrades.

According to a corporate alert published on Monday, the vulnerability (known as CVE-2024-53961) affects Adobe ColdFusion versions 2023 and 2021 and is caused by a path traversal hole that allows attackers to read any file on servers that are susceptible.

Adobe acknowledged today that CVE-2024-53961 has a known proof-of-concept that could result in an arbitrary file system read. The company also warned users that the flaw has been given a “Priority 1” severity rating because it is more likely to be targeted by exploits in the wild for a particular product version and platform read more about Adobe warns of critical ColdFusion bug with PoC exploit code.

Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.

Leave a Reply

Your email address will not be published. Required fields are marked *