vBulletin fixes critical pre-auth RCE flaw with public exploit

Summary

A critical pre-authentication remote code execution (RCE) vulnerability in vBulletin software enables unauthenticated attackers to execute arbitrary PHP code by exploiting a template rendering flaw. The vulnerability has a publicly available exploit, increasing the risk of widespread attacks.

IFF Assessment

FOE

The discovery of a critical vulnerability with a public exploit poses a significant threat to organizations using vBulletin, as it allows for easy exploitation by malicious actors.

Severity

9.8 Critical (AI Estimated)

This vulnerability is rated critical due to its high attack vector (network), user interaction (none), and significant impact on confidentiality, integrity, and availability, especially with a public exploit available.

Defender Context

Organizations using vBulletin should prioritize patching this critical vulnerability immediately, as attackers can exploit it remotely without authentication. The existence of a public exploit means attackers are likely already scanning for and exploiting vulnerable instances.

Read Full Story →