E23-gk0o1
CVSS:
8.6 CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N
False Positive:
f
Variants:
1
Year:
2023
Description
This strike exploits an insecure deserialization vulnerability in Adobe ColdFusion. The vulnerability is due to deserialization of untrusted data when processing HTTP parameters sent to ColdFusion Component (CFC) endpoints. A remote, unauthenticated, attacker could exploit this vulnerability by injecting crafted CFML tags into logs and then trigger the exploit by requesting the log file. Successful exploitation could result in arbitrary code execution in the security context of SYSTEM.
CVE
References
https://attackerkb.com/topics/F36ClHTTIQ/cve-2023-26360/rapid7-analysis