CVE-2023-44350
About
Adobe ColdFusion versions 2023.5 (and earlier) and 2021.11 (and earlier) are affected by an Deserialization of Untrusted Data vulnerability that could result in Arbitrary code execution. Exploitation of this issue does not require user interaction.
Rainforest analyst review
Adobe ColdFusion 2023.5 and 2021.11 and earlier deserialize untrusted data unsafely, and the result is arbitrary code execution with no user interaction required. An attacker sends crafted serialized data to a reachable ColdFusion server and gets code running on it — remote, unauthenticated, and direct. This is the highest-consequence class of web-server flaw, and ColdFusion typically runs application servers that sit close to sensitive data.
ColdFusion deserialization bugs have a long, ugly track record of being exploited in the wild, several landing on CISA's known-exploited list, so this isn't a hypothetical class. Adobe explicitly notes exploitation needs no user interaction, which is exactly the profile that draws fast proof-of-concept development and broad scanning. Internet-facing ColdFusion is a perennial target, and unauthenticated RCE against it should be assumed to attract attention quickly.
We treat this as top of the queue. The work is finding every ColdFusion instance — including forgotten and legacy application servers, which is where ColdFusion notoriously lingers — confirming which are internet-reachable, and getting them onto fixed builds without delay. Given the history, we also prime detection for exploitation attempts against these hosts rather than assuming patching will land before the scanners do.
References
Related CVEs
Frequently asked questions
What is CVE-2023-44350?
Adobe ColdFusion versions 2023.5 (and earlier) and 2021.11 (and earlier) are affected by an Deserialization of Untrusted Data vulnerability that could result in Arbitrary code execution. Exploitation of this issue does not require user interaction.
How severe is CVE-2023-44350?
CVE-2023-44350 carries a CVSS 3.1 base score of 9.8, rated critical. On the Rainforest Risk Index — which weighs the severity alongside how easy the flaw is to reach and how broad its impact is — it scores 99 out of 100, in the critical band.
How is CVE-2023-44350 exploited?
According to the CVSS vector (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H): attack vector Network, attack complexity Low, privileges required None, user interaction None. Impact on confidentiality High, integrity High and availability High.
Which products are affected by CVE-2023-44350?
Public advisories list the following as affected: coldfusion. Check the references on this page for the exact versions each vendor confirms.
How do I fix CVE-2023-44350?
Apply the fix the vendor published — the references on this page link to the primary advisories and patches. When patching can't happen right away, reduce the exposure of the affected component and watch it for exploitation attempts. Rainforest customers see this vulnerability correlated to their own assets and prioritized by real exposure, not by score alone.
Empower Your Security Strategy with Rainforest
Discover vulnerabilities early, prioritize critical threats, and protect what truly matters. Rainforest streamlines your security operations, saving you time and reducing costs, so you can focus on what drives your business forward.
