CVE-2025-61811

8.4

Adobe · ColdFusion

Adobe ColdFusion is susceptible to an improper access control vulnerability that allows a high-privileged attacker to achieve arbitrary code execution via path traversal.

Executive summary

Adobe ColdFusion versions 2025.4, 2023.16, 2021.22 and earlier contain a critical access control flaw that exposes systems to arbitrary code execution.

Vulnerability

The vulnerability is identified as a path traversal flaw (CWE-22) that permits an authenticated attacker with high privileges to bypass security restrictions and execute malicious code in the context of the current user. The attack vector is network-based and does not require user interaction to succeed.

Business impact

The ability for an attacker to execute arbitrary code with the permissions of the ColdFusion service poses a severe risk to organizational infrastructure. Given the CVSS score of 8.4, this vulnerability could lead to total system compromise, unauthorized data exfiltration, or the deployment of persistent threats within the internal network.

Remediation

Immediate Action: Apply the security updates provided in the Adobe security bulletin APSB25-105 immediately to patch the affected instances.

Proactive Monitoring: Review web server and application logs for suspicious path traversal patterns, such as sequences involving double dots or encoded directory separators.

Compensating Controls: Deploy Web Application Firewall (WAF) rules designed to detect and block malicious path traversal attempts targeting ColdFusion endpoints.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Due to the potential for arbitrary code execution and the severity of the flaw, administrators must prioritize the application of the vendor-supplied patches. Organizations should verify that all ColdFusion environments are updated to the versions specified in the Adobe advisory to eliminate this risk entirely.

More Adobe CVEs

Sources