CVE-2020-10145: High severity adobe coldfusion vulnerability
The Adobe ColdFusion installer fails to set a secure access-control list (ACL) on the default installation directory, such as C:\ColdFusion2021\. By default, unprivileged users can create files in this directory structure, which creates a privilege-escalation vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-10145?
CVE-2020-10145 is a vulnerability in the Adobe ColdFusion installer that allows unprivileged users to create files in the default installation directory, leading to privilege escalation.
What is the severity of CVE-2020-10145?
CVE-2020-10145 has a severity rating of 7.8 (High).
Which software versions are affected by CVE-2020-10145?
Adobe ColdFusion versions 2016, 2018, and 2021 are affected by CVE-2020-10145.
How does CVE-2020-10145 impact security?
CVE-2020-10145 allows unprivileged users to create files in the default installation directory of Adobe ColdFusion, creating a privilege escalation vulnerability.
Where can I find more information about CVE-2020-10145?
You can find more information about CVE-2020-10145 at the following link: https://www.kb.cert.org/vuls/id/125331