icon

Digital safety starts here for both commercial and personal Use...

Defend Your Business Against the Latest WNY Cyber Threats We offer Safe, Secure and Affordable Solutions for your Business and Personal Networks and Devices.



WNYCyber is there to help you to choose the best service providers in Western New York... We DO NOT provide the services ourselves, as we are Internet Programmers who have to deak daily with Cyber Threats... (Ugghhh)... So we know what it's like and what it takes to protect OUR and OUR CUSTOMERS DATA... We built this Website to help steer you to those that can give you the best service at realistic and non-inflated prices. We do charge or collect any fees.

Critical Adobe ColdFusion Flaw Added to CISA's Exploited Vulnerability Catalog

Cyber Security Threat Summary:
CISA has added a critical flaw in Adobe ColdFusion to its catalog of actively exploited vulnerabilities. Tracked as CVE-2023-26359, the flaw relates to a deserialization bug residing in Adobe ColdFusion 2018 (Update 15 and earlier) and ColdFusion 2021 (Update 5 and earlier). “Deserialization (aka unmarshaling) refers to the process of reconstructing a data structure or an object from a byte stream. But when it's performed without validating its source or sanitizing its contents, it can lead to unexpected consequences such as code execution or denial-of-service (DoS)” (The Hacker News, 2023).

Security Officer Comments:
No details have been released regarding how the flaw is being abused in the wild. According to Adobe, the vendor stated that it is aware of the bug being exploited in very limited attacks targeting systems running ColdFusion.

It seems as though CVE-2023-26359 can be exploited in low-complexity attacks. As such a threat actor can execute remote arbitrary code without requiring user interaction.

Suggested Correction(s):
CVE-2023-26359 was patched back on March 14, 2023, with the release of ColdFusion 2018 and ColdFusion 2021. CISA is giving federal agencies until September 11, 2023, to apply the necessary patches and secure their systems.

Link(s):


https://thehackernews.com/2023/08/critical-adobe-coldfusion-flaw-added-to.html