PT-2001-2599 · Adobe · Coldfusion
Publicado
2001-12-31
·
Atualizado
2008-09-05
·
CVE-2001-1514
CVSS v2.0
10
Alta
| Vetor | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
ColdFusion versions 4.5 and 5
Description
The issue arises when ColdFusion is running on Windows with the advanced security sandbox type set to "operating system". It fails to properly pass the security context to child processes created with
CFEXECUTE and to child processes that call the CreateProcess function and are executed with CFOBJECT or end with the CFX extension. This allows attackers to execute programs with the permissions of the System account.Recommendations
For ColdFusion versions 4.5 and 5, consider restricting the use of
CFEXECUTE and CFOBJECT until a proper fix is applied to ensure that child processes are executed with the correct security context. Additionally, limit the execution of files with the CFX extension to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability. Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Coldfusion