CVE-2020-9672: High severity adobe coldfusion vulnerability
Adobe ColdFusion 2016 update 15 and earlier versions, and ColdFusion 2018 update 9 and earlier versions have a dll search-order hijacking vulnerability. Successful exploitation could lead to privilege escalation.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability identifier for this Adobe ColdFusion vulnerability?
The vulnerability identifier for this Adobe ColdFusion vulnerability is CVE-2020-9672.
What is the severity of CVE-2020-9672?
The severity of CVE-2020-9672 is high with a score of 7.8.
What is the affected software for this vulnerability?
The affected software for this vulnerability is Adobe ColdFusion 2016 update 15 and earlier versions, and ColdFusion 2018 update 9 and earlier versions.
What is the description of this vulnerability?
This vulnerability in Adobe ColdFusion 2016 update 15 and earlier versions, and ColdFusion 2018 update 9 and earlier versions allows for dll search-order hijacking, which could lead to privilege escalation.
How can this vulnerability be exploited?
This vulnerability can be exploited by exploiting the dll search-order hijacking vulnerability in Adobe ColdFusion 2016 update 15 and earlier versions, and ColdFusion 2018 update 9 and earlier versions.