Intrusion Prevention

Adobe.ColdFusion.OOXML.XXE.Information.Disclosure

Description

This indicates an attack attempt against an Information Disclousre vulnerability in Adobe ColdFusion.
The vulnerability is due to insufficient validation in the the Office Open XML (OOXML) component, when parsing an XML external entity (XXE). A remote attacker may be able to read arbitrary files in the targeted system via a crafted OOXML document.

Affected Products

Adobe Systems ColdFusion 11 prior to Update 10
Adobe Systems ColdFusion 10 prior to Update 21

Impact

Information Disclosure: Remote attackers can gain sensitive information from vulnerable systems.

Recommended Actions

Apply the latest update from the vendor.
https://helpx.adobe.com/security/products/coldfusion/apsb16-30.html

CVE References

CVE-2016-4264

Other References

APSB16-30