Nov. 21, 2023, 9 a.m. | McCaulay Hudson

NCC Group Research Blog research.nccgroup.com

Multiple vulnerabilities identified in Adobe ColdFusion allow an unauthenticated attacker to obtain the service account NTLM password hash, verify the existence of a file or directory on the underlying operating system, and configure central config server settings.

account adobe adobe coldfusion advisory attacker coldfusion deserialization directory file gadgets hash ntlm operating system password server service service account settings system technical technical advisories technical advisory unauthenticated verify vulnerabilities vulnerability research

Azure DevSecOps Cloud Engineer II

@ Prudent Technology | McLean, VA, USA

Security Engineer III - Python, AWS

@ JPMorgan Chase & Co. | Bengaluru, Karnataka, India

SOC Analyst (Threat Hunter)

@ NCS | Singapore, Singapore

Managed Services Information Security Manager

@ NTT DATA | Sydney, Australia

Senior Security Engineer (Remote)

@ Mattermost | United Kingdom

Penetration Tester (Part Time & Remote)

@ TestPros | United States - Remote