First published: Tue May 13 2025(Updated: )
ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. A high-privileged attacker could leverage this vulnerability to bypass security mechanisms and execute code. Exploitation of this issue does not require user interaction and scope is changed.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe ColdFusion | <2025.1<2023.13<2021.19 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-43559 has a high severity rating due to its potential to allow arbitrary code execution.
To fix CVE-2025-43559, you should update Adobe ColdFusion to the latest version recommended by Adobe.
CVE-2025-43559 affects ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier.
CVE-2025-43559 can be exploited by attackers to execute arbitrary code within the context of the current user.
Yes, additional security measures should be considered alongside updating ColdFusion to mitigate risks from CVE-2025-43559.