logo

Code injection or backdoor: A new look at Ivanti’s CVE-2021-44529

ID: 0bbba5e5-150a-518a-875b-77c2db8f2ef1

STIX ID: report--0bbba5e5-150a-518a-875b-77c2db8f2ef1

Feed Name: GreyNoise Labs

Threat Score
30/100

Date Published: 2024-02-16

Date Updated: 2026-04-27

Author: Ron Bowes

...
...

This post examines a backdoor embedded in the now-defunct csrf-magic PHP library that implements remote code execution by concatenating and base64-decoding cookie values (CVE-2021-44529). The author deobfuscates the PHP payload, explains the trigger conditions (first cookie == 'ab' and at least four cookies, with the last three forming the base64 payload), and notes that Metasploit and GreyNoise signatures exist but that active exploitation appears limited, making this primarily a historical/forensic finding.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.