Millions of websites could be subjected to arbitrary code execution and total server compromise in malware intrusions exploiting a critical vulnerability in the antivirus system of CloudLinux's all-around server security platform Imunify360, reports Security Affairs.
Attacks exploiting the flaw involve the deployment of an illicit payload that prompts the Imunify360 AV's faulty deobfuscator to call risky PHP functions, which subsequently leads to arbitrary command execution and full hosting environment breaches, according to an analysis from Patchstack. Researchers said that active deobfuscation by Imunify360 AV during analysis is necessary for the exploit to function.
"Remote attackers can embed specifically crafted obfuscated PHP that matches imunify360AV (AI-bolit) deobfuscation signatures. The deobfuscator will execute extracted functions on attacker-controlled data, allowing execution of arbitrary system commands or arbitrary PHP code. Impact ranges from website compromise to full server takeover depending on hosting configuration and privileges," said Patchstack, which noted the issue to affect Imunify360, ImunifyAV, and ImunifyAV+. Patches have already been issued by CloudLinux late last month.
Attacks exploiting the flaw involve the deployment of an illicit payload that prompts the Imunify360 AV's faulty deobfuscator to call risky PHP functions, which subsequently leads to arbitrary command execution and full hosting environment breaches, according to an analysis from Patchstack. Researchers said that active deobfuscation by Imunify360 AV during analysis is necessary for the exploit to function.
"Remote attackers can embed specifically crafted obfuscated PHP that matches imunify360AV (AI-bolit) deobfuscation signatures. The deobfuscator will execute extracted functions on attacker-controlled data, allowing execution of arbitrary system commands or arbitrary PHP code. Impact ranges from website compromise to full server takeover depending on hosting configuration and privileges," said Patchstack, which noted the issue to affect Imunify360, ImunifyAV, and ImunifyAV+. Patches have already been issued by CloudLinux late last month.




