First published: Sat May 19 2018(Updated: )
Adobe ColdFusion Update 5 and earlier versions, ColdFusion 11 Update 13 and earlier versions have an exploitable Insecure Library Loading vulnerability. Successful exploitation could lead to local privilege escalation.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe ColdFusion | =11.0 | |
Adobe ColdFusion | =11.0-update1 | |
Adobe ColdFusion | =11.0-update10 | |
Adobe ColdFusion | =11.0-update11 | |
Adobe ColdFusion | =11.0-update12 | |
Adobe ColdFusion | =11.0-update13 | |
Adobe ColdFusion | =11.0-update2 | |
Adobe ColdFusion | =11.0-update3 | |
Adobe ColdFusion | =11.0-update4 | |
Adobe ColdFusion | =11.0-update5 | |
Adobe ColdFusion | =11.0-update6 | |
Adobe ColdFusion | =11.0-update7 | |
Adobe ColdFusion | =11.0-update8 | |
Adobe ColdFusion | =11.0-update9 | |
Adobe ColdFusion | =2016 | |
Adobe ColdFusion | =2016-update1 | |
Adobe ColdFusion | =2016-update2 | |
Adobe ColdFusion | =2016-update3 | |
Adobe ColdFusion | =2016-update4 | |
Adobe ColdFusion | =2016-update5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-4938 has a high severity rating due to its potential for local privilege escalation.
To fix CVE-2018-4938, users should update Adobe ColdFusion to the latest version or apply the necessary security patches provided by Adobe.
CVE-2018-4938 is caused by an insecure library loading mechanism that allows unauthorized access to privileged functions.
Adobe ColdFusion versions 11.0 and earlier, including all updates up to and including Update 5, are affected by CVE-2018-4938.
The exploitation of CVE-2018-4938 could allow an attacker to gain elevated privileges on the affected system, compromising its security.