CVE-2024-12828 (CVSS 9.9): Webmin-Schwachstelle macht eine Million Server anfällig für RCE

Teilen:

The popular web-based system administration tool, Webmin, has been found to harbor a critical security vulnerability (CVE-2024-12828) that could allow attackers to seize control of servers. With an estimated one million installations worldwide, the impact of this vulnerability could be widespread.

The vulnerability, assigned a CVSS score of 9.9, stems from a command injection flaw within Webmin’s CGI request handling. Essentially, the software fails to properly sanitize user-supplied input, enabling attackers to inject malicious commands that are then executed with root privileges.

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Webmin. Authentication is required to exploit this vulnerability,” the advisory notes.

What makes this vulnerability particularly dangerous is that it can be exploited by less-privileged Webmin users. This means that even if an attacker doesn’t have full administrative access, they could potentially escalate their privileges and take complete control of the server.

The exploitability of CVE-2024-12828 could have devastating consequences, including:

  • Full server compromise
  • Unauthorized access to sensitive data
  • Deployment of malicious scripts and ransomware
  • Use of compromised servers as platforms for further attacks

The vulnerability was discovered by Trend Micro’s Zero Day Initiative and has been addressed in Webmin version 2.111. All Webmin and Virtualmin administrators are strongly urged to update their installations immediately.

Quelle

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
1:56 am, Juli 2, 2025
Wetter-Symbol 20°C
L: 19° | H: 22°
aufgelockerte Bewölkung
Luftfeuchtigkeit: 77 %
Druck: 1015 mb
Wind: 7 mph NNE
Windböe: 0 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 50%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 4:48 am
Sonnenuntergang: 9:20 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 10:00 pm
Wetter-Symbol
19° | 22°°C 0.26 mm 26% 11 mph 80 % 1022 mb 0 mm/h
Tomorrow 10:00 pm
Wetter-Symbol
14° | 26°°C 0 mm 0% 13 mph 55 % 1028 mb 0 mm/h
Fr. Juli 04 10:00 pm
Wetter-Symbol
15° | 26°°C 0 mm 0% 12 mph 57 % 1028 mb 0 mm/h
Sa. Juli 05 10:00 pm
Wetter-Symbol
15° | 25°°C 1 mm 100% 15 mph 89 % 1022 mb 0 mm/h
So. Juli 06 10:00 pm
Wetter-Symbol
14° | 19°°C 1 mm 100% 13 mph 81 % 1012 mb 0 mm/h
Today 4:00 am
Wetter-Symbol
18° | 20°°C 0 mm 0% 5 mph 78 % 1015 mb 0 mm/h
Today 7:00 am
Wetter-Symbol
19° | 19°°C 0 mm 0% 8 mph 80 % 1015 mb 0 mm/h
Today 10:00 am
Wetter-Symbol
21° | 21°°C 0 mm 0% 6 mph 73 % 1017 mb 0 mm/h
Today 1:00 pm
Wetter-Symbol
19° | 19°°C 0.2 mm 20% 7 mph 71 % 1017 mb 0 mm/h
Today 4:00 pm
Wetter-Symbol
21° | 21°°C 0.26 mm 26% 8 mph 45 % 1019 mb 0 mm/h
Today 7:00 pm
Wetter-Symbol
24° | 24°°C 0 mm 0% 11 mph 32 % 1020 mb 0 mm/h
Today 10:00 pm
Wetter-Symbol
18° | 18°°C 0 mm 0% 10 mph 34 % 1022 mb 0 mm/h
Tomorrow 1:00 am
Wetter-Symbol
16° | 16°°C 0 mm 0% 7 mph 37 % 1025 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€89,377.95
-1.72%
Ethereum(ETH)
€2,033.11
-3.73%
Fesseln(USDT)
€0.85
-0.01%
XRP(XRP)
€1.84
-3.27%
Solana(SOL)
€124.34
-5.12%
USDC(USDC)
€0.85
-0.01%
Dogecoin(DOGE)
€0.133815
-4.39%
Shiba Inu(SHIB)
€0.000009
-2.09%
Pepe(PEPE)
€0.000008
-4.96%
Nach oben scrollen