Zero-day vulnerability in ColdFusion

Authentication bypass

The vulnerability was used to compromise website of the Washington state Administrative Office of the Courts (AOC).

Vulnerability details

Advisory: SB2013010401 - Multiple vulnerabilities in Adobe ColdFusion

Vulnerable component: ColdFusion

CVE-ID: CVE-2013-0632

CVSSv3 score: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H/E:H/RL:O/RC:C

CWE-ID: CWE-592 - Authentication Bypass Issues


The vulnerability allows a remote attacker to bypass authentication and gain unauthorized access to vulnerable system.

The vulnerability exists due to an error within administrator.cfc. A remote unauthenticated attacker can access Adobe ColdFusion application using a default empty password, login to the RDS component and leverage this session to access administrative web interface.

Successful exploitation of this vulnerability results in unauthorized access to Adobe ColdFusion.

Note: the vulnerability was being actively exploited.

Known APT campaigns:

Washington state Administrative Office of the Courts (AOC) breach

The attack happened between September, 2012 and February, 2013. The hackers stole 160,000 SSNs, 1M driver's license numbers.

Public Exploits: