By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Viral Trending contentViral Trending content
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
Reading: RCE flaw in ImunifyAV puts millions of Linux-hosted sites at risk
Notification Show More
Viral Trending contentViral Trending content
  • Home
  • Categories
    • World News
    • Politics
    • Sports
    • Celebrity
    • Business
    • Crypto
    • Tech News
    • Gaming News
    • Travel
  • Bookmarks
© 2024 All Rights reserved | Powered by Viraltrendingcontent
Viral Trending content > Blog > Tech News > RCE flaw in ImunifyAV puts millions of Linux-hosted sites at risk
Tech News

RCE flaw in ImunifyAV puts millions of Linux-hosted sites at risk

By admin 4 Min Read
Share
SHARE

The ImunifyAV malware scanner for Linux servers, used by tens of millions of websites, is vulnerable to a remote code execution vulnerability that could be exploited to compromise the hosting environment.

The issue affects versions of the AI-bolit malware scanning component prior to 32.7.4.0. The component is present in the Imunify360 suite, the paid ImunifyAV+, and in ImunifyAV, the free version of the malware scanner. 

According to security firm Patchstack, the vulnerability has been known since late October, when ImunifyAV’s vendor, CloudLinux, released fixes. Currently, the flaw has not been assigned an identifier.

Wiz

On November 10, the vendor backported the fix to older Imunify360 AV versions. In an advisory yesterday, CloudLinux warned customers about “a critical security vulnerability” and recommended to “update the software as soon as possible” to version 32.7.4.0

ImunifyAV is part of the Imunify360 security suite, mostly used by web-hosting providers or generic Linux shared hosting environments.

The product is typically installed at the hosting platform level, not by end-users directly. It is extremely common on shared hosting plans, managed WordPress hosting, cPanel/WHM servers, and Plesk servers.

Website owners rarely interact with it directly, but it is still a ubiquitous tool running silently behind 56 million websites, according to Imunify data from October 2024, which also claims more than 645,000 Imunify360 installations.

The root cause of the flaw is AI-bolit’s deobfuscation logic, which executes attacker-controlled function names and data extracted from obfuscated PHP files when trying to unpack malware for scanning it.

This occurs because the tool uses ‘call_user_func_array‘ without validating the function names, allowing execution of dangerous PHP functions such as system, exec, shell_exec, passthru, eval, and more.

Patchstack notes that exploiting the vulnerability requires Imunify360 AV to perform active deobfuscation during the analysis step, which is disabled in the default configuration of the standalone AI-Bolit CLI.

However, the Imunify360 integration of the scanner component is forcing an ‘always on’ state for background scans, on-demand scans, user-initiated scans, and rapid scans, which meets the exploitation requirement.

The researchers shared a proof of concept (PoC) exploit that creates a PHP file in the tmp directory, which will trigger remote code execution when scanned by the antivirus.

Proof of concept exploit
<strong>Proof of concept exploit</strong><br /><em>Source: Patchstack</em>

This could enable full website compromise, and if the scanner runs with elevated privileges in shared hosting setups, the implications could extend to full server takeover.

CloudLinux’s fix adds a whitelisting mechanism that only allows safe, deterministic functions to execute during deobfuscation, which blocks arbitrary function execution.

Despite the lack of clear warnings from the vendor or a CVE-ID that would help raise the alarm and track the issue, system administrators should upgrade to version v32.7.4.0 or newer.

Currently, there are no official instructions on how to check for compromise, no detection guidance, and no confirmation of active exploitation in the wild.

BleepingComputer has contacted CloudLinux with a request for comment, but we have not received a response by publishing time.

Wiz

It’s budget season! Over 300 CISOs and security leaders have shared how they’re planning, spending, and prioritizing for the year ahead. This report compiles their insights, allowing readers to benchmark strategies, identify emerging trends, and compare their priorities as they head into 2026.

Learn how top leaders are turning investment into measurable impact.

You Might Also Like

Samsung Galaxy S27 Ultra vs. S26 Ultra: S Pen Explained

Honor Magic 8 Pro Professional Imaging Kit Review

Our Favorite Amazon Streaming Stick Is Almost Half Off

How is Australia working to make data centres more sustainable?

Google Pixel 11 Design Leaked: Two key Changes

TAGGED: Immunify360, RCE, Remote Code Execution, Scanner, Vulnerability, Website, Website Takeover
Share This Article
Facebook Twitter Copy Link
Previous Article The Blood of Dawnwalker Gameplay Showcases Day and Night Quest Differences and Botched Vampires
Next Article The 17 Best Gifts for Plant Lovers We’d Buy Ourselves (2025)
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

- Advertisement -
Ad image

Latest News

Are Tiger Woods & Vanessa Trump Still Together? All About Their Relationship Now
Celebrity
Fist of the North Star’s Kenshiro is Coming to Fatal Fury: City of the Wolves in June
Gaming News
OpenAI’s Video Plagiarism App Sora Was Reportedly Losing $1 Million A Day
Gaming News
Samsung Galaxy S27 Ultra vs. S26 Ultra: S Pen Explained
Tech News
Hasselbaink has very obvious Chelsea solution but he’s right with one thing – opinion
Sports
Looking for top-performing fund of FY26? Nippon India Taiwan Equity Fund wins crown with 171%+ return
Business
Alleged $54M Uranium Finance hacker faces 30 years in prison
Crypto

About Us

Welcome to Viraltrendingcontent, your go-to source for the latest updates on world news, politics, sports, celebrity, tech, travel, gaming, crypto news, and business news. We are dedicated to providing you with accurate, timely, and engaging content from around the globe.

Quick Links

  • Home
  • World News
  • Politics
  • Celebrity
  • Business
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
  • Sports
  • Crypto
  • Tech News
  • Gaming News
  • Travel

Trending News

cageside seats

Unlocking the Ultimate WWE Experience: Cageside Seats News 2024

Investing £5 a day could help me build a second income of £329 a month!

Brussels unveils plans for a European Degree but struggles to explain why

cageside seats
Unlocking the Ultimate WWE Experience: Cageside Seats News 2024
May 22, 2024
Investing £5 a day could help me build a second income of £329 a month!
March 27, 2024
Brussels unveils plans for a European Degree but struggles to explain why
March 27, 2024
Trump evokes more anger and fear from Democrats than Biden does from Republicans, AP-NORC poll shows
March 28, 2024
© 2024 All Rights reserved | Powered by Vraltrendingcontent
  • About Us
  • Contact US
  • Disclaimer
  • Privacy Policy
  • Terms of Service
Welcome Back!

Sign in to your account

Lost your password?