The vulnerability was used to compromise website of the Washington state Administrative Office of the Courts (AOC).
Vulnerability details
Advisory: SB2013010401 - Multiple vulnerabilities in Adobe ColdFusion
Vulnerable component: ColdFusion
CVE-ID: CVE-2013-0632
CVSSv3 score: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:H/RL:O/RC:C
CWE-ID: CWE-592 - Authentication Bypass Issues
Description:
The vulnerability allows a remote attacker to bypass authentication and gain unauthorized access to vulnerable system.
The vulnerability exists due to an error within administrator.cfc. A remote unauthenticated attacker can access Adobe ColdFusion application using a default empty password, login to the RDS component and leverage this session to access administrative web interface.
Successful exploitation of this vulnerability results in unauthorized access to Adobe ColdFusion.
Note: the vulnerability was being actively exploited.Known APT campaigns:
Washington state Administrative Office of the Courts (AOC) breach
The attack happened between September, 2012 and February, 2013. The hackers stole 160,000 SSNs, 1M driver's license numbers.
Public Exploits:
- Adobe ColdFusion 9 - Administrative Login Bypass (Metasploit) [Exploit-DB]
- Adobe ColdFusion 9 - Administrative Login Bypass [Exploit-DB]
- Adobe ColdFusion APSB13-03 - Remote Exploit (Metasploit) [Exploit-DB]
External links:
http://www.adobe.com/support/security/advisories/apsa13-01.html
http://www.adobe.com/support/security/bulletins/apsb13-03.html
https://www.symantec.com/security_response/attacksignatures/detail.jsp?asid=27201
https://www.acunetix.com/vulnerabilities/web/adobe-coldfusion-9-administrative-login-bypass
https://vulners.com/metasploit/MSF:EXPLOIT/MULTI/HTTP/COLDFUSION_RDS
http://www.livehacking.com/category/vulnerability/adobe/
http://www.pcworld.com/article/2025406/adobe-patches-actively-exploited-coldfusion-vulnerabilities.h...
http://www.carehart.org/blog/client/index.cfm/2013/1/2/Part2_serious_security_threat
https://www.scmagazine.com/weakness-in-adobe-coldfusion-allowed-court-hackers-access-to-160k-ssns/ar...
http://www.itnews.com.au/news/a-million-drivers-licenses-possibly-stolen-via-coldfusion-hole-342953
http://krebsonsecurity.com/tag/amcrin/