CVE-2025-61810

8.4

Adobe · ColdFusion

Adobe ColdFusion is vulnerable to a deserialization of untrusted data flaw that allows a highly privileged attacker to execute arbitrary code.

Executive summary

Adobe ColdFusion contains a critical deserialization vulnerability that could allow a high privileged attacker to achieve arbitrary code execution.

Vulnerability

This vulnerability involves the insecure deserialization of untrusted data, specifically triggered when a high privileged attacker provides maliciously crafted serialized data to the application. Successful exploitation requires user interaction and results in arbitrary code execution in the context of the current user.

Business impact

The ability for an attacker to execute arbitrary code on a server hosting Adobe ColdFusion represents a total compromise of the application environment. With a CVSS score of 8.4, this flaw poses a severe risk to data confidentiality, integrity, and availability, potentially leading to unauthorized access to sensitive corporate information and the disruption of critical business services.

Remediation

Immediate Action: Apply the security updates provided by Adobe in the official advisory (APSB25-105) as soon as they are available for your specific deployment.

Proactive Monitoring: Review web server and application logs for suspicious serialized data patterns or unexpected execution of child processes associated with the ColdFusion service.

Compensating Controls: Implement strict network access controls to limit the reachability of the ColdFusion management interface to authorized administrative systems only.

Exploitation status

Public Exploit Available: No (exploit_available: unknown)

Analyst recommendation

Given the potential for arbitrary code execution, this vulnerability should be treated with high priority. Organizations must monitor the official Adobe security portal for the release of patches and prepare to deploy them across all affected ColdFusion environments immediately upon availability to minimize the window of exposure.

More Adobe CVEs

Sources