CVE-2016-4264 Information

Description

The Office Open XML (OOXML) feature in Adobe ColdFusion 10 before Update 21 and 11 before Update 10 allows remote attackers to read arbitrary files or send TCP requests to intranet servers via a crafted OOXML spreadsheet containing an external entity declaration in conjunction with an entity reference related to an XML External Entity (XXE) issue.

CVSS Vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N

Reference

http://legalhackers.com/advisories/Adobe-ColdFusion-11-XXE-Exploit-CVE-2016-4264.txt http://www.securityfocus.com/archive/1/539374/100/0/threaded http://www.securityfocus.com/bid/92684 http://www.securitytracker.com/id/1036708 https://helpx.adobe.com/security/products/coldfusion/apsb16-30.html https://www.exploit-db.com/exploits/40346/

Attack Complexity

LOW

Privileges Required

NONE

User Interaction Required

NONE

Scope

NONE

Confidentiality Impact

CHANGED

Integrity Impact

HIGH

Availability Impact

NONE

Base Score

NONE

Base Severity

8.6

Share on: