First published: Fri Jul 17 2020(Updated: )
Adobe ColdFusion 2016 update 15 and earlier versions, and ColdFusion 2018 update 9 and earlier versions have a dll search-order hijacking vulnerability. Successful exploitation could lead to privilege escalation.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe ColdFusion | =2016 | |
Adobe ColdFusion | =2016-update1 | |
Adobe ColdFusion | =2016-update10 | |
Adobe ColdFusion | =2016-update11 | |
Adobe ColdFusion | =2016-update12 | |
Adobe ColdFusion | =2016-update13 | |
Adobe ColdFusion | =2016-update14 | |
Adobe ColdFusion | =2016-update15 | |
Adobe ColdFusion | =2016-update2 | |
Adobe ColdFusion | =2016-update3 | |
Adobe ColdFusion | =2016-update4 | |
Adobe ColdFusion | =2016-update5 | |
Adobe ColdFusion | =2016-update6 | |
Adobe ColdFusion | =2016-update7 | |
Adobe ColdFusion | =2016-update8 | |
Adobe ColdFusion | =2016-update9 | |
Adobe ColdFusion | =2018 | |
Adobe ColdFusion | =2018-update1 | |
Adobe ColdFusion | =2018-update2 | |
Adobe ColdFusion | =2018-update3 | |
Adobe ColdFusion | =2018-update4 | |
Adobe ColdFusion | =2018-update5 | |
Adobe ColdFusion | =2018-update6 | |
Adobe ColdFusion | =2018-update7 | |
Adobe ColdFusion | =2018-update8 | |
Adobe ColdFusion | =2018-update9 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this Adobe ColdFusion vulnerability is CVE-2020-9673.
The severity of CVE-2020-9673 is high with a CVSS score of 7.8.
The affected software for this vulnerability is Adobe ColdFusion 2016 update 15 and earlier versions, and ColdFusion 2018 update 9 and earlier versions.
Successful exploitation of this vulnerability could lead to privilege escalation.
Yes, Adobe has released updates to address this vulnerability. It is recommended to update to the latest version of Adobe ColdFusion.