We've just released a security hotfix for ColdFusion 10 running on Windows, this fix addresses a possible DoS threat when using IIS. This can (and should) be installed using the ColdFusion 10 Administrator update option.