Vulnerability record · CVE-2025-43562 · published 13 May 2025
CVE-2025-43562: Adobe ColdFusion OS command injection allows arbitrary code execution
Adobe · Coldfusion
Adobe ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier fail to neutralize special elements used in OS commands, allowing OS command injection. Successful exploitation leads to arbitrary code execution in the context of the current user, and the changed scope means impact can extend beyond the vulnerable component.
Description
ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier are affected by an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability that could result in arbitrary code execution in the context of the current user. A high-privileged attacker could leverage this vulnerability to bypass security mechanisms and execute code. Exploitation of this issue does not require user interaction and scope is changed.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H
Automated analysis
high priorityCritical CVSS score of 9.1 with changed scope and very high EPSS percentile, though exploitation requires high privileges and no KEV listing or public exploit is confirmed.
What it is
Adobe ColdFusion versions 2025.1, 2023.13, 2021.19 and earlier fail to neutralize special elements used in OS commands, allowing OS command injection. Successful exploitation leads to arbitrary code execution in the context of the current user, and the changed scope means impact can extend beyond the vulnerable component.
Impact
An attacker who already holds high privileges can bypass security mechanisms and execute arbitrary operating system commands, potentially compromising the host and adjacent systems.
Attack surface
The vulnerability is network-reachable (AV:N) with no user interaction required (UI:N), but the CVSS vector requires high privileges (PR:H), so the attacker must already have an authenticated high-privileged position on the target.
Exploitation
Not listed in CISA KEV and no public exploit references are provided, but EPSS is 0.45123 (98.7th percentile), indicating elevated predicted exploitation activity.
What to do
- Apply the Adobe ColdFusion security update referenced in advisory APSB25-52 for the affected versions.
- Restrict network access to ColdFusion administrative interfaces and services to trusted management networks only.
- Audit and minimize accounts with high privileges on ColdFusion servers, enforcing least privilege and strong authentication.
- Monitor and constrain OS command execution paths available to the ColdFusion service account.
- Review ColdFusion server logs and configuration for unauthorized administrative changes after patching.
Detection
- Monitor ColdFusion process trees for unexpected child processes such as cmd.exe, powershell.exe, or /bin/sh spawned by the ColdFusion service.
- Alert on suspicious OS command strings or shell metacharacters in ColdFusion application and server logs.
- Track high-privileged ColdFusion account activity for anomalous administrative actions or configuration changes.
- Correlate network connections to ColdFusion management ports with subsequent process creation events on the host.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://helpx.adobe.com/security/products/coldfusion/apsb25-52.html | Vendor Advisory |
Track CVE-2025-43562 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2025-43562), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.