CVE-2020-10145

Publication date

2021-05-27 20:55:10

Family

certcc

State

PUBLISHED

Description

The Adobe ColdFusion installer fails to set a secure access-control list (ACL) on the default installation directory, such as C:ColdFusion2021. By default, unprivileged users can create files in this directory structure, which creates a privilege-escalation vulnerability.