Remote code execution
RCE · A flaw that lets an attacker run their own commands on a target server or device over the internet; usually among the most severe flaws.
- 01
Why it matters
Remote code execution hands the attacker the keys to the system: data can be stolen, ransomware installed or the server used for other attacks. It usually comes from unpatched software, unsafe file uploads or processing untrusted data. Once such a flaw is announced, exploitation can start within hours.
- 02
Example
A site's upload field checks only the file extension. The attacker uploads a script disguised as an image and runs commands on the server by opening the file's address.
- 03
Common mistake
Leaving critical updates for the next maintenance window. When a remote code execution flaw is announced, update immediately; if that is not possible, add a temporary protection rule and extra monitoring.
- 04
Related terms
Related services and guides
Let's talk about your project.
Tell us what you need; we will define the scope together.