APP: Adobe ColdFusion RMI Registry Insecure Deserialization Remote Code Execution

An insecure deserialization vulnerability has been reported in the Flex integration service of Adobe ColdFusion. A remote, unauthenticated attacker can exploit this vulnerability by sending maliciously crafted serialized data to the target application. Successful exploitation could result in arbitrary code execution in the context of SYSTEM.

Extended Description

Adobe ColdFusion has an Untrusted Data Deserialization vulnerability. This affects Update 4 and earlier versions for ColdFusion 2016, and Update 12 and earlier versions for ColdFusion 11.

Affected Products

Adobe coldfusion

References

BugTraq: 100708

CVE: CVE-2017-11283

Short Name
APP:MISC:ADOBE-COLDFUSION-RCE
Severity
Major
Recommended
True
Recommended Action
Drop
Category
APP
Keywords
Adobe CVE-2017-11283 CVE-2017-11284 Code ColdFusion Deserialization Execution Insecure RMI Registry Remote bid:100708
Release Date
11/07/2017
Supported Platforms

srx-branch-19.3

vsrx3bsd-19.2

srx-19.4

vsrx3bsd-19.4

srx-branch-19.4

vsrx-19.4

vsrx-19.2

srx-19.3

srx-branch-12.3

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx-12.3

vmx-19.3

srx-12.3

Sigpack Version
3690
False Positive
Unknown
Vendors

Adobe

CVSS Score

7.5

Found a potential security threat?