Malicious HEIC Images Can Trigger Remote Code Execution on WordPress Servers

A malicious HEIC image can become a route to remote code execution on a WordPress server. Researchers have demonstrated an attack chain that turns a normal Media Library upload into code execution in the PHP-FPM process that runs the site. The risk comes from libheif, a widely used component that reads HEIC, HEIF and AVIF […]

This article has been indexed from Cyber Security News

Read the original article: