Security News > 2024 > June > TellYouThePass ransomware exploits recent PHP RCE flaw to breach servers
The TellYouThePass ransomware gang has been exploiting the recently patched CVE-2024-4577 remote code execution vulnerability in PHP to deliver webshells and execute the encryptor payload on target systems.
TellYouThePass ransomware is known for quickly jumping on public exploits for vulnerabilities with a wide impact.
In the latest attacks spotted by researchers at cybersecurity company Imperva, TellYouThePass exploits the critical-severity CVE-2024-4577 bug to execute arbitrary PHP code, using the Windows mshta.
CVE-2024-4577 is a critical RCE vulnerability that impacts all PHP versions since 5.x. It stems from unsafe character encoding conversions on Windows when used in CGI mode.
According to a report from Censys yesterday, there are more than 450,000 exposed PHP servers that could be vulnerable to the CVE-2024-4577 RCE vulnerability, most of them located in the United States and Germany.
PHP fixes critical RCE flaw impacting all versions for Windows.
News URL
Related news
- Over 50,000 Tinyproxy servers vulnerable to critical RCE flaw (source)
- City of Wichita breach claimed by LockBit ransomware gang (source)
- Helsinki suffers data breach after hackers exploit unpatched flaw (source)
- PoC exploit released for RCE zero-day in D-Link EXO AX4800 routers (source)
- MediSecure e-script firm hit by ‘large-scale’ ransomware data breach (source)
- Aussie cops probe MediSecure's 'large-scale ransomware data breach' (source)
- QNAP QTS zero-day in Share feature gets public RCE exploit (source)
- OmniVision discloses data breach after 2023 ransomware attack (source)
- Ransomware Attacks Exploit VMware ESXi Vulnerabilities in Alarming Pattern (source)
- Exploit released for maximum severity Fortinet RCE bug, patch now (source)
Related Vulnerability
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2024-06-09 | CVE-2024-4577 | OS Command Injection vulnerability in multiple products In PHP versions 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, when using Apache and PHP-CGI on Windows, if the system is set up to use certain code pages, Windows may use "Best-Fit" behavior to replace characters in command line given to Win32 API functions. | 9.8 |