CVE-2024-41874: ColdFusion | Deserialization of Untrusted Data (CWE-502)
ColdFusion versions 2023.9, 2021.15 and earlier are affected by a Deserialization of Untrusted Data vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability by providing crafted input to the application, which when deserialized, leads to execution of malicious code. Exploitation of this issue does not require user interaction.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-41874?
CVE-2024-41874 is rated as a critical vulnerability that can lead to arbitrary code execution.
How do I fix CVE-2024-41874?
To mitigate CVE-2024-41874, update Adobe ColdFusion to the latest version or apply the security patches released by Adobe.
What versions of Adobe ColdFusion are affected by CVE-2024-41874?
CVE-2024-41874 affects Adobe ColdFusion versions 2023.9, 2021.15, and earlier.
Can an attacker exploit CVE-2024-41874 remotely?
Yes, an attacker can exploit CVE-2024-41874 remotely by sending crafted input to the vulnerable application.
What are the potential impacts of CVE-2024-41874 on my system?
The potential impacts of CVE-2024-41874 include unauthorized remote access and execution of arbitrary code in the context of the current user.