PT-2025-15645 · Adobe · Coldfusion

Published

2025-04-08

·

Updated

2025-04-22

·

CVE-2025-24447

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: ColdFusion versions 2025.0 and earlier ColdFusion versions 2023.12 ColdFusion versions 2021.18
Description: The issue is related to a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction, where a victim must open a malicious file. The vulnerability is associated with deficiencies in the deserialization mechanism, allowing a remote attacker to execute arbitrary code.
Recommendations: For ColdFusion versions 2025.0 and earlier, update to a version that includes a fix for the Deserialization of Untrusted Data vulnerability. For ColdFusion versions 2023.12, apply the necessary security patches or updates to resolve the vulnerability. For ColdFusion versions 2021.18, consider applying configuration changes or workarounds to mitigate the risk of exploitation until a patch is available. As a temporary workaround, consider restricting the use of deserialization functions to minimize the risk of exploitation.

Fix

Deserialization of Untrusted Data

Weakness Enumeration

Related Identifiers

BDU:2025-04063
CVE-2025-24447

Affected Products

Coldfusion