TimThumb Plugin Remote Code Execution

  Severity: CRITICAL
  Advisory Date: JUL 21, 2015

  DESCRIPTION

This rule is a heuristic based rule to detect malicious php code embedded within gif, jpg and png image files. An attacker may use maliciously crafted image file to do remote code execution and take control of the victim's host machine.

  TREND MICRO PROTECTION INFORMATION

Apply associated Trend Micro DPI Rules.

  SOLUTION

  Trend Micro Deep Security DPI Rule Number: 1004880
  Trend Micro Deep Security DPI Rule Name: 1004880 - Identified Suspicious Image File With Embedded PHP Code

  AFFECTED SOFTWARE AND VERSION

  • Microsoft Windows
  • PHP