Threat Intelligence Brief
New cPanel Flaw Lets a Hosting Account With Mail Privileges Run Code as Root
Source: thehackernews.com
Threat Risk: High
Victim: Enterprise Organizations & Affected Platforms
Incident: New cPanel Flaw Lets a Hosting Account With Mail Privileges Run Code as Root
Impact: Unauthenticated remote exploitation, data theft, or compromise of exposed infrastructure.
Attacker: Active Threat Actors / Exploitation Groups
Analysis: cPanel has patched a flaw that it says lets a single hosting account take control of an entire server. An authenticated account holder with mail-related privileges can create files of their choosing on the server through EmailTrack and, from there, run code as the root user.
Victim: Enterprise Organizations & Affected Platforms
Incident: New cPanel Flaw Lets a Hosting Account With Mail Privileges Run Code as Root
Impact: Unauthenticated remote exploitation, data theft, or compromise of exposed infrastructure.
Attacker: Active Threat Actors / Exploitation Groups
Analysis: cPanel has patched a flaw that it says lets a single hosting account take control of an entire server. An authenticated account holder with mail-related privileges can create files of their choosing on the server through EmailTrack and, from there, run code as the root user.
cPanel published the advisory on September 8 and says every supported version of cPanel and WHM is affected….
Recommendations: Apply emergency vendor updates, monitor network perimeters, and isolate vulnerable endpoints.; Review authentication logs for anomalous remote commands.
Source: The Hacker News
Editorial note: this post summarizes high-priority intelligence and links to primary telemetry.
View Primary Telemetry →
View Primary Telemetry →