By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Viral Trending contentViral Trending content
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
Reading: RCE flaw in ImunifyAV puts millions of Linux-hosted sites at risk
Notification Show More
Viral Trending contentViral Trending content
  • Home
  • Categories
    • World News
    • Politics
    • Sports
    • Celebrity
    • Business
    • Crypto
    • Tech News
    • Gaming News
    • Travel
  • Bookmarks
© 2024 All Rights reserved | Powered by Viraltrendingcontent
Viral Trending content > Blog > Tech News > RCE flaw in ImunifyAV puts millions of Linux-hosted sites at risk
Tech News

RCE flaw in ImunifyAV puts millions of Linux-hosted sites at risk

By admin 4 Min Read
Share
SHARE

The ImunifyAV malware scanner for Linux servers, used by tens of millions of websites, is vulnerable to a remote code execution vulnerability that could be exploited to compromise the hosting environment.

The issue affects versions of the AI-bolit malware scanning component prior to 32.7.4.0. The component is present in the Imunify360 suite, the paid ImunifyAV+, and in ImunifyAV, the free version of the malware scanner. 

According to security firm Patchstack, the vulnerability has been known since late October, when ImunifyAV’s vendor, CloudLinux, released fixes. Currently, the flaw has not been assigned an identifier.

Wiz

On November 10, the vendor backported the fix to older Imunify360 AV versions. In an advisory yesterday, CloudLinux warned customers about “a critical security vulnerability” and recommended to “update the software as soon as possible” to version 32.7.4.0

ImunifyAV is part of the Imunify360 security suite, mostly used by web-hosting providers or generic Linux shared hosting environments.

The product is typically installed at the hosting platform level, not by end-users directly. It is extremely common on shared hosting plans, managed WordPress hosting, cPanel/WHM servers, and Plesk servers.

Website owners rarely interact with it directly, but it is still a ubiquitous tool running silently behind 56 million websites, according to Imunify data from October 2024, which also claims more than 645,000 Imunify360 installations.

The root cause of the flaw is AI-bolit’s deobfuscation logic, which executes attacker-controlled function names and data extracted from obfuscated PHP files when trying to unpack malware for scanning it.

This occurs because the tool uses ‘call_user_func_array‘ without validating the function names, allowing execution of dangerous PHP functions such as system, exec, shell_exec, passthru, eval, and more.

Patchstack notes that exploiting the vulnerability requires Imunify360 AV to perform active deobfuscation during the analysis step, which is disabled in the default configuration of the standalone AI-Bolit CLI.

However, the Imunify360 integration of the scanner component is forcing an ‘always on’ state for background scans, on-demand scans, user-initiated scans, and rapid scans, which meets the exploitation requirement.

The researchers shared a proof of concept (PoC) exploit that creates a PHP file in the tmp directory, which will trigger remote code execution when scanned by the antivirus.

Proof of concept exploit
<strong>Proof of concept exploit</strong><br /><em>Source: Patchstack</em>

This could enable full website compromise, and if the scanner runs with elevated privileges in shared hosting setups, the implications could extend to full server takeover.

CloudLinux’s fix adds a whitelisting mechanism that only allows safe, deterministic functions to execute during deobfuscation, which blocks arbitrary function execution.

Despite the lack of clear warnings from the vendor or a CVE-ID that would help raise the alarm and track the issue, system administrators should upgrade to version v32.7.4.0 or newer.

Currently, there are no official instructions on how to check for compromise, no detection guidance, and no confirmation of active exploitation in the wild.

BleepingComputer has contacted CloudLinux with a request for comment, but we have not received a response by publishing time.

Wiz

It’s budget season! Over 300 CISOs and security leaders have shared how they’re planning, spending, and prioritizing for the year ahead. This report compiles their insights, allowing readers to benchmark strategies, identify emerging trends, and compare their priorities as they head into 2026.

Learn how top leaders are turning investment into measurable impact.

You Might Also Like

Apple AI Pin Specs Leak: Dual Cameras, No Screen & More

The diverse responsibilities of a principal software engineer

OpenAI Backs Bill That Would Limit Liability for AI-Enabled Mass Deaths or Financial Disasters

Google’s Fitbit Tease has me More Excited for Garmin’s Whoop Rival

Why the TCL NXTPAPER 14 Is One of the Best Tablets for Musicians and Sheet Music Reading

TAGGED: Immunify360, RCE, Remote Code Execution, Scanner, Vulnerability, Website, Website Takeover
Share This Article
Facebook Twitter Copy Link
Previous Article The Blood of Dawnwalker Gameplay Showcases Day and Night Quest Differences and Botched Vampires
Next Article The 17 Best Gifts for Plant Lovers We’d Buy Ourselves (2025)
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

- Advertisement -
Ad image

Latest News

JPMorgan CEO Jamie Dimon says he’s ‘learned and relearned’ to not make big decisions when he’s tired on Fridays
Business
Apple AI Pin Specs Leak: Dual Cameras, No Screen & More
Tech News
A ‘glass-like’ battlefield: German Army chief on the future of warfare
World News
Polymarket Sees Record $153M Daily Volume After Chainlink Integration
Crypto
Natasha Lyonne Then & Now: See Before & After Photos of the Actress Here
Celebrity
Cult Hit Doki Doki Literature Club Fights Removal From Google Play Store Over ‘Depiction Of Sensitive Themes’
Gaming News
Dead as Disco Launches Into Early Access on May 5th, Groovy New Gameplay Released
Gaming News

About Us

Welcome to Viraltrendingcontent, your go-to source for the latest updates on world news, politics, sports, celebrity, tech, travel, gaming, crypto news, and business news. We are dedicated to providing you with accurate, timely, and engaging content from around the globe.

Quick Links

  • Home
  • World News
  • Politics
  • Celebrity
  • Business
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
  • Sports
  • Crypto
  • Tech News
  • Gaming News
  • Travel

Trending News

cageside seats

Unlocking the Ultimate WWE Experience: Cageside Seats News 2024

Investing £5 a day could help me build a second income of £329 a month!

JPMorgan CEO Jamie Dimon says he’s ‘learned and relearned’ to not make big decisions when he’s tired on Fridays

cageside seats
Unlocking the Ultimate WWE Experience: Cageside Seats News 2024
May 22, 2024
Investing £5 a day could help me build a second income of £329 a month!
March 27, 2024
JPMorgan CEO Jamie Dimon says he’s ‘learned and relearned’ to not make big decisions when he’s tired on Fridays
April 10, 2026
Brussels unveils plans for a European Degree but struggles to explain why
March 27, 2024
© 2024 All Rights reserved | Powered by Vraltrendingcontent
  • About Us
  • Contact US
  • Disclaimer
  • Privacy Policy
  • Terms of Service
Welcome Back!

Sign in to your account

Lost your password?