IT Pro is supported by its audience. When you purchase through links on our site, we may earn an affiliate commission. Learn more

Flaw found in Apache Web Server

A new flaw discovered in Apache Web Server allows hackers to take control of system privileges, researchers claim.

Apache

A new flaw has been discovered in Apache Web Server that could allow cyber criminals to take control of system privileges, according to a security research firm.

Sense of Security (SoS) released an advisory claiming the core mod_isapi module in the most popular open source HTTP server could be targeted to induce the vulnerability.

The report said: "By sending a specially crafted request followed by a reset packet it is possible to trigger a vulnerability in Apache mod_isapi that will unload the target ISAPI module from memory."

It continued to claim that although this would be unloaded, function pointers would still remain, allowing attackers to take control - what SoS calls "a dangling pointer vulnerability."

The vulnerability was given a high severity rating by the researchers who said it definitely affected version 2.2.14 on the Windows platform but could also affect others.

The simple solution and advice for users is to upgrade to version 2.2.15. Users can also download the proof of concept from SoS from here.

IT PRO contacted Apache for comment on the new flaw but it had not responded to our request at the time of publication.

Featured Resources

Meeting the future of education with confidence

How the switch to digital learning has created an opportunity to meet the needs of every student, always

Free Download

The Total Economic Impact™ of IBM Cloud Pak® for Watson AIOps with Instana

Cost savings and business benefits

Free Download

The business value of the transformative mainframe

Modernising on the mainframe

Free Download

Technology reimagined

Why PCaaS is perfect for modern schools

Free Download

Recommended

Selecting a fit-for-purpose server platform for datacentre infrastructure
Whitepaper

Selecting a fit-for-purpose server platform for datacentre infrastructure

15 Jun 2022
What is the semantic web?
Business strategy

What is the semantic web?

8 Jun 2022
Modernise your server infrastructure for speed and security
Whitepaper

Modernise your server infrastructure for speed and security

9 Feb 2022
Modernise your server infrastructure for speed and security
Whitepaper

Modernise your server infrastructure for speed and security

9 Feb 2022

Most Popular

How to boot Windows 11 in Safe Mode
Microsoft Windows

How to boot Windows 11 in Safe Mode

7 Jun 2022
The top programming languages you need to learn for 2022
Careers & training

The top programming languages you need to learn for 2022

23 Jun 2022
Attracting and retaining talent through training
Sponsored

Attracting and retaining talent through training

13 Jun 2022