CVE-2001-1514

C

oldFusion 4.5 and 5, when running on Windows with the advanced security sandbox type set to "operating system," does not properly pass security context to (1) child processes created with <CFEXECUTE> and (2) child processes that call the CreateProcess function and are executed with <CFOBJECT> or end with the CFX extension, which allows attackers to execute programs with the permissions of the System account.

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:macromedia:coldfusion:4.5:*:*:*:*:*:*:*
cpe:2.3:a:macromedia:coldfusion:5.0:*:*:*:*:*:*:*

History

20 Nov 2024, 23:37

Type Values Removed Values Added
References () http://www.macromedia.com/v1/Handlers/index.cfm?ID=22263 - Vendor Advisory () http://www.macromedia.com/v1/Handlers/index.cfm?ID=22263 - Vendor Advisory

Information

Published : 2001-12-31 05:00

Updated : 2025-04-03 01:03


NVD link : CVE-2001-1514

Mitre link : CVE-2001-1514

CVE.ORG link : CVE-2001-1514


JSON object : View

Products Affected