CVS-exploit of Tomcat 9/10/11

Sebastiaan, instead of running the tomcat9.exe (or tomcat9w.exe), you would want to run the luceew.exe, which is found alongside those in that [lucee]\tomcat\bin folder. It offers the UI you were seeking–and yep, it ends up editing the reg entry for you.

But it’s not new to Lucee 6. It was this way in Lucee 5 as well (for example, I have a reply in another thread here sharing this same tip in 2019.) And I can confirm that, yes, it works on Windows 2022 as well.

I certainly appreciate it’s not “common knowledge” that’s suggested often. People who don’t run the Lucee installer for Windows would not likely know of it, so that they often suggest editing files–which don’t end up affecting Lucee running as a service. And even folks having experience with the Tomcat installers for Windows and its service might try the Tomcat9w.exe–but again that doesn’t work here.

Hope this helps others who may ever seek the same sort of solution. :slight_smile: