LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2018-4939: Adobe ColdFusion Deserialization of Untrusted Data Vulnerability

RBRecent Breaches Vulnerability Intelligence·Nov 3, 2021
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
May 3, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2018-4939 to its Known Exploited Vulnerabilities catalog on Nov 3, 2021, with a federal patch deadline of May 3, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Adobe ColdFusion contains a deserialization of untrusted data vulnerability that could allow for code execution.

CVE-2018-4939 is a deserialization of untrusted data vulnerability in Adobe ColdFusion that could allow an attacker to achieve code execution. For IT and security teams running ColdFusion application servers, this matters because successful abuse can give an attacker control over the host process and the applications it serves. Confirm all version, configuration, and fix details directly against the vendor advisory.

How it works

This issue is classified as CWE-502, deserialization of untrusted data. In products that accept serialized objects or similar structured input, the application may reconstruct objects from data supplied by a client without adequately validating that the data is safe. When an attacker can supply crafted serialized content that the ColdFusion runtime deserializes, the reconstruction process can trigger unintended object creation or method invocation that leads to code execution in the context of the ColdFusion process.

Exact exploit mechanics, required request formats, and preconditions are not detailed in the provided facts. Defenders should treat any untrusted input path that reaches a deserializer as potentially dangerous and verify the precise attack surface described in Adobe’s advisory for this CVE.

Am I affected? How to find it in your systems

Adobe ColdFusion is commonly deployed as an application server for web and internal business applications, often on Windows or Linux hosts behind web servers or load balancers. Inventory every system that runs ColdFusion, including development, test, and production instances, as well as any embedded or secondary installations.

How to remediate

Patch first. Apply the updates Adobe released for this vulnerability exactly as described in the vendor advisory. CISA’s required action is to apply updates per vendor instructions. After patching, restart services as directed and verify the new build is running.

If you can't patch immediately

Until the vendor update can be installed, reduce exposure with compensating controls. These do not replace the patch.

If your data may have been exposed

Actively exploited vulnerabilities of this class can lead to full compromise of the application server and subsequent data access or ransomware deployment; the provided facts state that known ransomware use is not documented for this CVE. If you have reason to believe an instance was reachable and unpatched during a period of suspected activity, follow your incident-response process: isolate, preserve logs, and assess what data the ColdFusion process could access. You can also run a free exposure scan of your email addresses against known breach data sets to check whether credentials or identities tied to your environment have appeared in prior breaches.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedAdobe · ColdFusion
WeaknessCWE-502
Added to CISA KEVNov 3, 2021
Federal patch deadlineMay 3, 2022
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities