Skip to content
COOEY

EXPOSURES › CVE-2023-38203

CVE-2023-38203

CRITICAL ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2024-01-08 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2023-38203 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 85/100 ransomwarerceexploited-in-wildunpatched

Adobe ColdFusion suffered a critical deserialization vulnerability allowing remote code execution, linked to ransomware attacks.

The vulnerability in Adobe ColdFusion allowed attackers to execute arbitrary code through deserialization of untrusted data, directly enabling ransomware deployment. DIB organizations must ensure all ColdFusion instances are patched immediately, as this flaw was actively exploited in the wild and represents a severe compliance risk under CMMC/NIST 800-171 for unpatched critical vulnerabilities.

Shame score — A critical, actively exploited vulnerability linked to ransomware that Adobe failed to patch promptly, demonstrating severe negligence and avoidable exposure.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Adobe ColdFusion contains a deserialization of untrusted data vulnerability that allows for code execution.

AFFECTED FEDRAMP PRODUCTS · 8
PRODUCTSTATUS
Adobe Acrobat Sign for Government
Adobe
Authorized
Adobe Analytics
Adobe
Authorized
Adobe Campaign
Adobe
Authorized
Adobe Connect Managed Services (ACMS-GC)
Adobe
Authorized
Adobe Creative Cloud for Enterprise
Adobe
Authorized
Adobe Document Cloud (PDF Services & Adobe Sign)
Adobe
Authorized
Adobe Experience Manager Managed Services (AEMMS-GC)
Adobe
Authorized
Adobe Learning Manager
Adobe
Authorized