Skip to content
COOEY

EXPOSURES › CVE-2024-20767

CVE-2024-20767

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2024-12-16 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2024-20767 ↗
⌖ EXPLOITED IN THE WILD SHAME 65/100 exploited-in-wildunpatcheddata-breachsupply-chain

Adobe ColdFusion's unpatched improper access control flaw (CVE-2024-20767) lets attackers modify restricted files via exposed admin panels.

This improperly limited pathname access vulnerability in ColdFusion allows attackers to access or modify restricted files through an internet-exposed admin panel, creating a high-risk exposure for DIB organizations relying on legacy ColdFusion systems. Because ColdFusion has a historically poor security posture with frequent critical RCE and deserialization flaws, this unpatched CVE poses a significant compliance risk under FedRAMP/NIST 800-171 requirements for timely patching and access control integrity.

Shame score — ColdFusion's legacy status combined with this unpatched access control flaw creates a high-risk exposure for DIB organizations, though the vendor disclosed it and it is not a zero-day.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Adobe ColdFusion contains an improper access control vulnerability that could allow an attacker to access or modify restricted files via an internet-exposed admin panel.

AFFECTED FEDRAMP PRODUCTS · 8
PRODUCTSTATUS
Adobe Acrobat Sign for Government
Adobe
Authorized
Adobe Analytics
Adobe
Authorized
Adobe Campaign
Adobe
Authorized
Adobe Connect Managed Services (ACMS-GC)
Adobe
Authorized
Adobe Creative Cloud for Enterprise
Adobe
Authorized
Adobe Document Cloud (PDF Services & Adobe Sign)
Adobe
Authorized
Adobe Experience Manager Managed Services (AEMMS-GC)
Adobe
Authorized
Adobe Learning Manager
Adobe
Authorized