Researchers detailed how CVE-2024-2961, a long-standing buffer overflow in glibc's iconv implementation for ISO-2022-CN-EXT, can be exploited to achieve remote code execution in PHP applications. The technique, dubbed CNEXT, builds on earlier work around PHP filter chains and error-based file-read oracles, showing how php://filter can be abused not just to read files but to manipulate PHP heap allocations and corrupt internal memory structures. By chaining filters such as convert.iconv, zlib.inflate, and dechunk, the exploit can steer allocator behavior and overwrite zend_mm_heap hooks so that PHP ultimately invokes system().
The write-up says the method is reliable across PHP 7.0.0 through 8.3.7 and can be delivered in a single GET request, significantly raising the impact of otherwise limited file-read primitives. A demonstrated attack used the WordPress BuddyForms flaw CVE-2023-26326 to gain file-read access and then escalate to code execution, while the researchers warned that the same path could affect other PHP file-read sinks, including XXE and SQL injection scenarios involving LOAD DATA LOCAL INFILE. The findings also revive attention on PHP filter-chain abuse first explored in prior research, showing that seemingly minor disclosure bugs can become full server compromise when combined with glibc and PHP internals.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
3 events from the most recent confirmed update back to the earliest known activity.
Lexfo published part 1 of its CNEXT research on exploiting CVE-2024-2961, a long-standing buffer overflow in glibc's iconv implementation for ISO-2022-CN-EXT conversions. The write-up showed how PHP's php://filter behavior and heap manipulation can turn a file-read primitive into reliable remote code execution across PHP 7.0.0 through 8.3.7.
A vulnerability in the WordPress BuddyForms plugin, tracked as CVE-2023-26326, was disclosed and later used as an example file-read primitive for PHP exploitation. In the referenced material, it serves as the initial access point before escalation to code execution.
Synacktiv published research describing PHP filter chains that enable file reads via an error-based oracle. This established a practical file-read primitive in PHP applications that later exploitation work could build on.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.