EXPOSURES › CVE-2024-20767
CVE-2024-20767
HIGH ⌖ ON CISA KEV · EXPLOITEDAdobe ColdFusion's unpatched improper access control flaw (CVE-2024-20767) lets attackers modify restricted files via exposed admin panels.
This improperly limited pathname access vulnerability in ColdFusion allows attackers to access or modify restricted files through an internet-exposed admin panel, creating a high-risk exposure for DIB organizations relying on legacy ColdFusion systems. Because ColdFusion has a historically poor security posture with frequent critical RCE and deserialization flaws, this unpatched CVE poses a significant compliance risk under FedRAMP/NIST 800-171 requirements for timely patching and access control integrity.
Shame score — ColdFusion's legacy status combined with this unpatched access control flaw creates a high-risk exposure for DIB organizations, though the vendor disclosed it and it is not a zero-day.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Adobe ColdFusion contains an improper access control vulnerability that could allow an attacker to access or modify restricted files via an internet-exposed admin panel.
| PRODUCT | STATUS |
|---|---|
| Adobe Acrobat Sign for Government Adobe |
Authorized |
| Adobe Analytics Adobe |
Authorized |
| Adobe Campaign Adobe |
Authorized |
| Adobe Connect Managed Services (ACMS-GC) Adobe |
Authorized |
| Adobe Creative Cloud for Enterprise Adobe |
Authorized |
| Adobe Document Cloud (PDF Services & Adobe Sign) Adobe |
Authorized |
| Adobe Experience Manager Managed Services (AEMMS-GC) Adobe |
Authorized |
| Adobe Learning Manager Adobe |
Authorized |