Close Menu
Indo Guard OnlineIndo Guard Online
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
What's Hot

Critical vulnerability in Anthropic MCP exposes machines for remote feats

July 1, 2025

Ta829 and Unk_greensec share tactics and infrastructure in current malware

July 1, 2025

A new drawback in the IDES as a Visual Studio code allows for malicious bypassing bypassing the verified status

July 1, 2025
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram YouTube
Indo Guard OnlineIndo Guard Online
Subscribe
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
Indo Guard OnlineIndo Guard Online
Home » Adobe Patches 11 Critical Disadvantages Cold Fuzing on the background of 30 revealed total vulnerabilities
Global Security

Adobe Patches 11 Critical Disadvantages Cold Fuzing on the background of 30 revealed total vulnerabilities

AdminBy AdminApril 9, 2025No Comments3 Mins Read
Adobe ColdFusion
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link


09 April 2025Red LakshmananSoftware / vulnerability

Adobe Coldfusion

Adobe is liberated Security updates to correct fresh sets of security flaws, including several critical errors in Coldfusion 2025, 2023 and 2021, which could lead to arbitrary file reading and code execution.

Of 30 deficiency in product 11 are evaluated by critical in seriousness –

  • Cve-2025-2446 (CVSS assessment: 9.1) – Incorrect vulnerability of entry check that may result in the read arbitrary file system
  • Cve-2025-2447 (CVSS assessment: 9.1) – Deaserization of the unreliable vulnerability of the data that may lead to an arbitrary code
  • Cve-2025-30281 (CVSS assessment: 9.1) – Incorrect vulnerability of access control that may lead to an read file system
  • Cve-2025-30282 (CVSS assessment: 9.1) – Incorrect authentication vulnerability that can lead to arbitrary code
  • Cve-2025-30284 (CVSS assessment: 8.0) – Deaserization of the unreliable vulnerability of the data that may lead to an arbitrary code
  • Cve-2025-30285 (CVSS assessment: 8.0) – Deaserization of the unreliable vulnerability of the data that may lead to an arbitrary code
  • Cve-2025-30286 (CVSS assessment: 8.0) – vulnerability of the introduction of the operating system that can lead to an arbitrary code
  • Cve-2025-30287 (CVSS assessment: 8.1) – Incorrect authentication vulnerability that may lead to an arbitrary code
  • Cve-2025-30288 (CVSS assessment: 7.8) – Incorrect vulnerability of access control that can lead to bypass security features
  • Cve-2025-30289 (CVSS assessment: 7.5) – vulnerability of the introduction of the operating system that can lead to arbitrary code
  • Cve-2025-30290 (CVSS assessment: 8.7) – vulnerability of the path that can lead to bypassing security features
Cybersecurity

“These updates decide the critical and important vulnerabilities that can lead to the read file system, the arbitrary code and security function,” Adobe – Note In advisory.

The vulnerabilities were resolved in the versions below –

  • Coldfusion 2021 Update 19
  • Coldfusion 2023 Update 13, and
  • Update Coldfusion 2025 1

The fixes were also released to solve multiple offs that write, and based on piles of buffer errors After the effects (Cve-2015-27182, Cve-2015-27183), Media Kader (Cve-2015-27194, Cve-2015-27195), Bridge (Cve-2015-27193), Premiere Pro (Cve-2015-27196), Photo show (Cve-2015-27198), Animate (Cve-2015-27199), and Frame (CVE-2025-30304, Cve-2025-30297, Cve-2025-30295), which may lead to an arbitrary code.

Adobe also noted that he did not know about any feats in any of the above deficiencies. Given this, it is important that users update their settings to the latest version to protect against potential threats.

Found this article interesting? Keep track of us further Youter  and LinkedIn To read more exclusive content we publish.





Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Admin
  • Website

Related Posts

Critical vulnerability in Anthropic MCP exposes machines for remote feats

July 1, 2025

Ta829 and Unk_greensec share tactics and infrastructure in current malware

July 1, 2025

A new drawback in the IDES as a Visual Studio code allows for malicious bypassing bypassing the verified status

July 1, 2025

New Mattery Model for Browser Safety: Closing Risk in Last Mile

July 1, 2025

Google Patches Critical Lack of Zero Day in the V8 Chrome engine after active operation

July 1, 2025

US arrests in North Korean IT -Work scheme; Captures 29 domains and raids 21 laptops

July 1, 2025
Add A Comment
Leave A Reply Cancel Reply

Loading poll ...
Coming Soon
Do You Like Our Website
: {{ tsp_total }}

Subscribe to Updates

Get the latest security news from Indoguardonline.com

Latest Posts

Critical vulnerability in Anthropic MCP exposes machines for remote feats

July 1, 2025

Ta829 and Unk_greensec share tactics and infrastructure in current malware

July 1, 2025

A new drawback in the IDES as a Visual Studio code allows for malicious bypassing bypassing the verified status

July 1, 2025

New Mattery Model for Browser Safety: Closing Risk in Last Mile

July 1, 2025

Google Patches Critical Lack of Zero Day in the V8 Chrome engine after active operation

July 1, 2025

US arrests in North Korean IT -Work scheme; Captures 29 domains and raids 21 laptops

July 1, 2025

Microsoft Removes Password Management from Authenticator app since August 2025

July 1, 2025

American agencies warn of Iranian protection cyber growth, OT networks and critical infrastructure

June 30, 2025
About Us
About Us

Provide a constantly updating feed of the latest security news and developments specific to Indonesia.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks

Critical vulnerability in Anthropic MCP exposes machines for remote feats

July 1, 2025

Ta829 and Unk_greensec share tactics and infrastructure in current malware

July 1, 2025

A new drawback in the IDES as a Visual Studio code allows for malicious bypassing bypassing the verified status

July 1, 2025
Most Popular

In Indonesia, crippling immigration ransomware breach sparks privacy crisis

July 6, 2024

Why Indonesia’s Data Breach Crisis Calls for Better Security

July 6, 2024

Indonesia’s plan to integrate 27,000 govt apps in one platform welcomed but data security concerns linger

July 6, 2024
© 2025 indoguardonline.com
  • Home
  • About us
  • Contact us
  • Privacy Policy

Type above and press Enter to search. Press Esc to cancel.