VORANT. Threat Intelligence Sign in Get the full feed

Adobe ColdFusion Deserialization Flaw Patched

medium vulnerability technology

IPA warns of a deserialization vulnerability in Adobe ColdFusion (CVE-2024-41874) that could allow arbitrary code execution and urges immediate patching.

Japan's IPA (Information-technology Promotion Agency) issued an advisory regarding CVE-2024-41874, a vulnerability in Adobe ColdFusion application server caused by improper validation of data prior to deserialization. If exploited, the flaw could allow a third party to execute arbitrary code on affected systems.

The advisory notes that damage could expand in the future and recommends that administrators apply the fixes provided by Adobe following the vendor's published procedures. No evidence of active exploitation is cited in the alert; it is a patch-now recommendation based on the risk of arbitrary code execution.

Mentioned in this report

Vulnerabilities CVE-2024-41874

Source reporting: https://www.ipa.go.jp/security/security-alert/2024/alert20240911.html

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free