Vulnerability Name: | CVE-2001-1514 (CCN-23481) | ||||||||
Assigned: | 2001-11-27 | ||||||||
Published: | 2001-11-27 | ||||||||
Updated: | 2008-09-05 | ||||||||
Summary: | ColdFusion 4.5 and 5, when running on Windows with the advanced security sandbox type set to "operating system," does not properly pass security context to (1) child processes created with <CFEXECUTE> and (2) child processes that call the CreateProcess function and are executed with <CFOBJECT> or end with the CFX extension, which allows attackers to execute programs with the permissions of the System account. | ||||||||
CVSS v3 Severity: | 10.0 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
| ||||||||
CVSS v2 Severity: | 10.0 High (CVSS v2 Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: MITRE Type: CNA CVE-2001-1514 Source: CCN Type: Macromedia Security Bulletin MPSB01-11 The CFEXECUTE tag should be disabled when using ColdFusion Sandbox Security (Operating System type) on Windows. Source: CONFIRM Type: Vendor Advisory http://www.macromedia.com/v1/Handlers/index.cfm?ID=22263 Source: CCN Type: OSVDB ID: 20225 ColdFusion CFEXECUTE / CFOBJECT Child Process Privilege Escalation Source: XF Type: UNKNOWN coldfusion-cfexecute-execute-code(23481) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
BACK |