Attacker Value
Unknown
(0 users assessed)
Exploitability
Unknown
(0 users assessed)
User Interaction
Unknown
Privileges Required
Unknown
Attack Vector
Unknown
3

CVE-2023-26359

Disclosure Date: March 14, 2023
Add MITRE ATT&CK tactics and techniques that apply to this CVE.

Description

Adobe ColdFusion versions 2018 Update 15 (and earlier) and 2021 Update 5 (and earlier) are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction.

Add Assessment

No one has assessed this topic. Be the first to add your voice to the community.

General Information

Vendors

  • Adobe

Products

  • ColdFusion

Additional Info

Technical Analysis

Note: The vulnerability initially analyzed as CVE-2023-26359 has been identified to be CVE-2023-26360. This change occurred after Adobe updated their advisory to re-classify CVE-2023-26360 from an Improper Access Control vulnerability to a Deserialization of Untrusted Data vulnerability. This change, in conjunction with privately reported information regarding CVE-2023-26359, let us reliably identify CVE-2023-26360. The AttackerKB Analysis for CVE-2023-26360 is now available here.