Adobe reported active exploitation of four critical vulnerabilities in ColdFusion affecting Windows, Macintosh, and UNIX systems. Advisory APSA13-01, issued in January 2013, identified CVE-2013-0625 and CVE-2013-0632 as remote authentication-bypass flaws that could enable server takeover, CVE-2013-0629 as a restricted-directory access vulnerability, and CVE-2013-0631 as an information-disclosure flaw involving a compromised server. The CVE record for CVE-2013-0629 specifies that ColdFusion 9.0, 9.0.1, 9.0.2, and 10 are vulnerable when a password is not configured and confirms exploitation in January 2013.
Adobe released priority 1 security hotfixes for ColdFusion 10, 9.0.2, 9.0.1, and 9.0, with installation instructions in bulletin APSB13-03. Administrators should apply the applicable fixes and restrict administrative access. For unsupported versions, including ColdFusion 8.x and earlier, Adobe recommended configuring password protection, disabling Remote Development Services after setting credentials, restricting administrative access, and removing unknown or unnecessary components.

See which actors are running it and whether you're in range.
8 events from the most recent confirmed update back to the earliest known activity.
CISA added Adobe ColdFusion authentication-bypass vulnerability CVE-2013-0632 to its Known Exploited Vulnerabilities Catalog. It required vendor-directed updates with a remediation deadline of March 24, 2022.
The published CVE record documented restricted-directory access in ColdFusion 9.0, 9.0.1, 9.0.2, and 10 when a password is not configured. It also identified exploitation in the wild.
Adobe released APSA13-01 warning of critical ColdFusion vulnerabilities and exploitation in the wild against customers. The advisory provided mitigation guidance, including password protections and restrictions on administrative access.
CVE-2013-0629 was exploited in the wild against Adobe ColdFusion in January 2013. The vulnerability allows attackers to access restricted directories when a password is not configured.
An Exploit-DB entry documents a Metasploit exploit for remote administrative authentication bypass in Adobe ColdFusion 9.
Adobe revised APSA13-01 to correct the ColdFusion versions vulnerable to CVE-2013-0625. The corrected affected-version list identified ColdFusion 9.0.2, 9.0.1, and 9.0.
Adobe updated APSA13-01 with information about security hotfixes for ColdFusion 10, 9.0.2, 9.0.1, and 9.0. The fixes addressed critical vulnerabilities, received priority rating 1, and were accompanied by installation instructions in APSB13-03.
Adobe updated APSA13-01 to identify CVE-2013-0632 as being exploited in the wild. The vulnerability could allow remote authentication bypass and potential takeover of ColdFusion 10 and supported ColdFusion 9 releases.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Correlate live exploitation activity against the software you actually run, and see where you're exposed.
6 references tracked. Mallory keeps watching after this page renders.
cve.org
Open sourceweb.nvd.nist.gov
Open sourceexploit-db.com
Open sourceadobe.com
Open sourceadobe.com
Open sourcecwe.mitre.org
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.