VYPR
High severity7.8NVD Advisory· Published May 27, 2021· Updated Jun 17, 2026

CVE-2020-10145

CVE-2020-10145

Description

The Adobe ColdFusion installer fails to set a secure access-control list (ACL) on the default installation directory, such as C:\ColdFusion2021\. By default, unprivileged users can create files in this directory structure, which creates a privilege-escalation vulnerability.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

5
  • cpe:2.3:a:adobe:coldfusion:2016:-:*:*:*:*:*:*+ 4 more
    • cpe:2.3:a:adobe:coldfusion:2016:-:*:*:*:*:*:*
    • cpe:2.3:a:adobe:coldfusion:2018:-:*:*:*:*:*:*
    • cpe:2.3:a:adobe:coldfusion:2021:-:*:*:*:*:*:*
    • (no CPE)
    • (no CPE)range: 2021

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.