CVE-2023-38203 is a critical Deserialization of Untrusted Data vulnerability affecting Adobe ColdFusion versions 2018u17, 2021u7, and 2023u1 and earlier. This flaw allows for arbitrary code execution without user interaction, posing a severe risk to affected systems. With a CVSS score of 9.8 (CRITICAL) and an EPSS score indicating high exploitability, it has a FAUCET Risk Score of 100/100. The vulnerability is actively exploited, including in known ransomware campaigns, and has garnered significant community discussion and media coverage, with Nuclei templates available for detection.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2018CPE matchmatch criteria | cpe:2.3:a:adobe:coldfusion:2018:-:*:*:*:*:*:* | ||
2018CPE matchmatch criteria | cpe:2.3:a:adobe:coldfusion:2018:update1:*:*:*:*:*:* | ||
2018CPE matchmatch criteria | cpe:2.3:a:adobe:coldfusion:2018:update10:*:*:*:*:*:* | ||
2018CPE matchmatch criteria | cpe:2.3:a:adobe:coldfusion:2018:update11:*:*:*:*:*:* | ||
2018CPE matchmatch criteria | cpe:2.3:a:adobe:coldfusion:2018:update12:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.