Another Monday, Another Major Adobe Vulnerability

Source: Bleeping Computer Another Monday, Another Major Adobe Vulnerability

Adobe ColdFusion Gets A Perfect 10

If you are running Adobe ColdFusion and haven’t patched since last Tuesday, you are not just a tempting target, you might already be a victim.  This particular vulnerability is a path traversal attack; a couple of special characters added to a public facing web address can give an attacker full  access to private directories they shouldn’t be able to even see.  With full access to your ColdFusion files, they could delete or modify them.  That would turn your website into a one stop infection site for anyone visiting.

In general Adobe ColdFusion is not used by small sites, instead it is preferred by larger enterprise sites which don’t know better than to use Adobe.  This means that unpatched sites you visit could well be just waiting to infect you and you’d have no way of knowing.  Stay careful out there.

Since November 2021, the U.S. Cybersecurity and Infrastructure Security Agency (CISA) has included 79 vulnerabilities in Adobe products in its catalog of actively exploited flaws, 10 of which have also been abused in ransomware attacks.

Video News

About The Author

Jeremy Hellstrom

Call it K7M.com, AMDMB.com, or PC Perspective, Jeremy has been hanging out and then working with the gang here for years. Apart from the front page you might find him on the BOINC Forums or possibly the Fraggin' Frogs if he has the time.

Leave a reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Latest Podcasts

Archive & Timeline

Previous 12 months
Explore: All The Years!