Proof-of-Concept (PoC) exploits for a zero-day vulnerability in the Apache web server have appeared online, revealing that the vulnerability is much more critical than initially disclosed.

See also: Vulnerability in popular parental control app Canopy
These exploits show that the scope of the vulnerability goes beyond path traversal, allowing attackers remote code execution (RCE) capabilities.
Apache remains one of the most popular web servers of choice with over 25% market share.
From so-called "path traversal" to remote code execution
The path traversal vulnerability in Apache's HTTP server, first reported by BleepingComputer, has been actively exploited by hackers before the Apache project was notified of the flaw in September or had a chance to fix it.
But yesterday's disclosure of the Apache path traversal webserver flaw, identified as CVE-2021-41773, was followed by PoC exploits that quickly appeared online.
But while the PoC exploits were being developed and collaborated on, another discovery came to light.
Attackers can abuse Apache servers running version 2.4.49 not only to read arbitrary files but also to execute arbitrary code on the servers.
See also: Vulnerability in VMware vCenter is still exploitable
Security researcher Hacker Fantastic noted that the flaw soon turns into a remote code execution (RCE) vulnerability on a Linuxif the server is configured to support CGI via mod_cgi.
If an attacker is able to upload a file via a path traversal exploit and set execute permissions on the file, they have now given themselves the ability to execute commands with the same privileges as the Apache process.
CERT vulnerability analyst Will Dormann and security researcher Tim Brown have also reported success with executing code on Windows machines.
While playing with the simple PoC on the Windows server, Dormann realized that accessing an EXE via the path traversal exploit in turn launched the binary on his server, as opposed to simply dumping the EXE's contents.
Not all installations are vulnerable
Although Shodan queries run by BleepingComputer show that over 112,000 Apache servers are running the vulnerable version 2.4.49, not all servers may be at risk.
The success of path traversal exploits depends on several factors, including whether the “mod-cgi” feature is enabled on the server and the default “Require all denied” option is missing from the configuration.
However, if all of the elements in the above criteria are met, there is a high possibility that the vulnerability could lead to arbitrary code execution. Server administrators should ensure that Apache HTTP server instances running versions 2.4.50 and later are updated.
See also: Millions of HP OMEN PCs affected by a serious vulnerability
Threat intel analyst Florian Roth provided Sigma rules to help detect an active zero-day exploit.
Information source: bleepingcomputer.com
