CVE-2023-3824 is a memory-safety vulnerability in PHP affecting versions 8.0.x before 8.0.30, 8.1.x before 8.1.22, and 8.2.x before 8.2.8. The flaw occurs when PHP loads a PHAR archive and reads PHAR directory entries. Insufficient length checking during parsing can cause a stack buffer overflow. Successful exploitation may corrupt process memory and can potentially be leveraged for remote code execution, depending on application behavior and exploitability conditions.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos (2 hidden).
This repository demonstrates a proof-of-concept exploit for PHP applications that allow PHAR file uploads and have 'phar.readonly = Off'. The main file, index.php, provides a web interface to upload a PHAR file. Upon upload, the script extracts a file named shell.php from the PHAR archive and writes it to the server's root directory, effectively deploying a webshell. The README provides setup instructions using Docker and shows how to use the webshell to execute a reverse shell command. The exploit targets PHP environments with insecure PHAR handling, enabling remote code execution via a webshell. The repository contains two files: a README with usage instructions and index.php with the exploit logic.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced only as part of repository names in attacker infrastructure/IoCs; no vulnerability details are provided in the content.
A suspected vulnerability (CVE-2023-3824) affecting older PHP deployments (notably PHP 8.1.2 in this account) that LockBitSupp claims may have enabled compromise of LockBit infrastructure during/around Operation Cronos.
A remote code execution flaw in PHP that law enforcement reportedly used to compromise LockBit servers during the takedown operation.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.