Security News > 2024 > June > TellYouThePass ransomware exploits recent PHP RCE flaw to breach servers
The TellYouThePass ransomware gang has been exploiting the recently patched CVE-2024-4577 remote code execution vulnerability in PHP to deliver webshells and execute the encryptor payload on target systems.
TellYouThePass ransomware is known for quickly jumping on public exploits for vulnerabilities with a wide impact.
In the latest attacks spotted by researchers at cybersecurity company Imperva, TellYouThePass exploits the critical-severity CVE-2024-4577 bug to execute arbitrary PHP code, using the Windows mshta.
CVE-2024-4577 is a critical RCE vulnerability that impacts all PHP versions since 5.x. It stems from unsafe character encoding conversions on Windows when used in CGI mode.
According to a report from Censys yesterday, there are more than 450,000 exposed PHP servers that could be vulnerable to the CVE-2024-4577 RCE vulnerability, most of them located in the United States and Germany.
PHP fixes critical RCE flaw impacting all versions for Windows.
News URL
Related news
- Helldown ransomware exploits Zyxel VPN flaw to breach networks (source)
- BT unit took servers offline after Black Basta ransomware breach (source)
- Week in review: Fortinet patches critical FortiManager 0-day, VMware fixes vCenter Server RCE (source)
- Fog ransomware targets SonicWall VPNs to breach corporate networks (source)
- Ransomware hits web hosting servers via vulnerable CyberPanel instances (source)
- LA housing authority confirms breach claimed by Cactus ransomware (source)
- Microsoft SharePoint RCE bug exploited to breach corporate network (source)
- Meet Interlock — The new ransomware targeting FreeBSD servers (source)
- Critical Veeam RCE bug now used in Frag ransomware attacks (source)
- New Ymir Ransomware Exploits Memory for Stealthy Attacks; Targets Corporate Networks (source)
Related Vulnerability
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2024-06-09 | CVE-2024-4577 | OS Command Injection vulnerability in multiple products In PHP versions 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, when using Apache and PHP-CGI on Windows, if the system is set up to use certain code pages, Windows may use "Best-Fit" behavior to replace characters in command line given to Win32 API functions. | 9.8 |