A malicious HEIC image can become a route to remote code execution on a WordPress server. Researchers have demonstrated an attack chain that turns a normal Media Library upload into code execution in the PHP-FPM process that runs the site. The risk comes from libheif, a widely used component that reads HEIC, HEIF and AVIF files. When WordPress... Weiterlesen: Malicious HEIC Images Can Trigger Remote Code Execution on WordPress …
Intelligence View
⚡ tsecurity.de Intelligence
Malicious HEIC Images Can Trigger Remote Code Execution on WordPress Servers
A malicious HEIC image can become a route to remote code execution on a WordPress server. Researchers have demonstrated an attack chain that turns a normal…
Cyber Threat Intelligence & Forensik
ATT&CK-Navigator · IoC-Radar · Exploit-Belege