First published: Thu May 27 2021(Updated: )
The Adobe ColdFusion installer fails to set a secure access-control list (ACL) on the default installation directory, such as C:\ColdFusion2021\. By default, unprivileged users can create files in this directory structure, which creates a privilege-escalation vulnerability.
Credit: cret@cert.org
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe ColdFusion | =2016 | |
Adobe ColdFusion | =2018 | |
Adobe ColdFusion | =2021 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-10145 is a vulnerability in the Adobe ColdFusion installer that allows unprivileged users to create files in the default installation directory, leading to privilege escalation.
CVE-2020-10145 has a severity rating of 7.8 (High).
Adobe ColdFusion versions 2016, 2018, and 2021 are affected by CVE-2020-10145.
CVE-2020-10145 allows unprivileged users to create files in the default installation directory of Adobe ColdFusion, creating a privilege escalation vulnerability.
You can find more information about CVE-2020-10145 at the following link: https://www.kb.cert.org/vuls/id/125331