Mmastodon TechnologyCybersecurity first seen 12 h ago, last 12 h ago, peak #7
Malicious HEIC images can trigger WordPress remote code execution
Original: A malicious HEIC image can turn a WordPress media upload into remote code execution. This exploit chain abuses a heap bu
A newly described exploit chain lets a malicious HEIC image turn a routine WordPress media upload into remote code execution. The attack abuses a heap buffer overflow in the libheif library during uncompressed HEIC decoding, then uses a memory disclosure via generated JPEG thumbnails to bypass ASLR. Security researchers are warning site administrators to patch and restrict image uploads.
Why now: WordPress powers a huge share of the web, so a media-upload flaw leading to full remote code execution is highly relevant to site owners and security teams.
Evidence
- A malicious HEIC image can turn a WordPress media upload into remote code execution. This exploit chain abuses a heap buffer overflow in libheif during uncompressed HEIC decoding, then uses a memory disclosure through generated JPEG thumbnails to bypass ASLR. The attacker can… · thecybersecguru@infosec.exchange · 1
API: https://socialmediatrends-api.osmike.com/v1/trends/1136669