HIGH
Adobe ColdFusion 2016 update 15 and earlier versions, and ColdFusion 2018 update 9 and earlier versions have a dll search-order hijacking vulnerability
Published Jul 17, 2020
7.8
HIGHCVSS 3.1
EPSS 1.04%
Description
Adobe ColdFusion 2016 update 15 and earlier versions, and ColdFusion 2018 update 9 and earlier versions have a dll search-order hijacking vulnerability. Successful exploitation could lead to privilege escalation.
Affected products
-
- Version update 15 and earlier versionsStatusaffectedConstraints-
- Version
-
- Version update 9 and earlier versionsStatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Adobe | Adobe ColdFusion 2016 | n/a |
| ||||||
| Adobe | Adobe ColdFusion 2018 | n/a |
|
OR
- 2016
- 2016
- 2016
- 2016
- 2016
- 2016
- 2016
- 2016
- 2016
- 2016
- 2016
- 2016
- 2016
- 2016
- 2016
- 2016
- 2018
- 2018
- 2018
- 2018
- 2018
- 2018
- 2018
- 2018
- 2018
- 2018
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (2)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-30456 Advisory
- https://helpx.adobe.com/security/products/coldfusion/apsb20-43.html x_refsource_CONFIRMVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-30456 | Advisory | |
| https://helpx.adobe.com/security/products/coldfusion/apsb20-43.html | x_refsource_CONFIRMVendor Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner adobe
Published Jul 17, 2020
Updated May 5, 2025
Reserved Mar 2, 2020
Link CVE-2020-9672
CISA Vulnrichment
Updated Apr 23, 2025
ENISA EUVD
EUVD-2020-30456 Assigner adobe
Published Jul 17, 2020
Updated May 5, 2025
Exploited since n/a
Link EUVD-2020-30456