TL;DR

A critical vulnerability in Adobe ColdFusion allows authenticated attackers to execute arbitrary code through the CAR file parsing feature.

What happened

["Remote attackers can exploit an RCE flaw in Adobe ColdFusion's CAR file parser", 'Exploitation requires authentication but can lead to full system compromise']

Why it matters for ops

['CAR file parsing is vulnerable to directory traversal attacks', 'Authenticated access allows for potential privilege escalation and data exfiltration']

Mitigation

  • Apply Adobe-provided security patches immediately
  • Restrict access to CAR file parsing functionality as much as possible

Action items

  • Update ColdFusion to the latest version with fixes
  • Review and restrict permissions for users with access to CAR files

Detection IOCs

  • Unusual network traffic from CAR file parser endpoint
  • Unexpected process execution within application server logs

Source link

http://www.zerodayinitiative.com/advisories/ZDI-26-070/