Known Exploited Vulnerabilities CVE-2018-4939 Mappings

Adobe ColdFusion Update 5 and earlier versions, ColdFusion 11 Update 13 and earlier versions have an exploitable Deserialization of Untrusted Data vulnerability. Successful exploitation could lead to arbitrary code execution.

Mappings

Capability ID Capability Description Mapping Type ATT&CK ID ATT&CK Name Notes
CVE-2018-4939 Adobe ColdFusion Deserialization of Untrusted Data Vulnerability primary_impact T1190 Exploit Public-Facing Application
CVE-2018-4939 Adobe ColdFusion Deserialization of Untrusted Data Vulnerability primary_impact T1133 External Remote Services
CVE-2018-4939 Adobe ColdFusion Deserialization of Untrusted Data Vulnerability exploitation_technique T1203 Exploitation for Client Execution
Comments
This deserialization vulnerability allows adversaries to insert their own objects into client software for potential execution.
References