peter bassill · operator
$ cve CVE-2024-4577 JSON

CVE-2024-4577 KEV EXPLOIT

9.8
CRITICAL · CVSS 3.1 · EPSS 100% (pctl 100)

Patch first

On CISA KEV — known exploited in the wild, due 2024-07-03.

Description

In PHP versions 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, when using Apache and PHP-CGI on Windows, if the system is set up to use certain code pages, Windows may use "Best-Fit" behavior to replace characters in command line given to Win32 API functions. PHP CGI module may misinterpret those characters as PHP options, which may allow a malicious user to pass options to PHP binary being run, and thus reveal the source code of scripts, run arbitrary PHP code on the server, etc.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS99.99% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-78
On CISA KEVyes — remediate by 2024-07-03
Public exploityes
Published2024-06-09
Last modified2026-06-17

CISA KEV

NamePHP-CGI OS Command Injection Vulnerability
Added2024-06-12
Due2024-07-03
Vendor / productPHP Group / PHP
Ransomware useknown

Affected (3)

VendorProduct
fedoraprojectfedora
microsoftwindows
phpphp

Public exploits

SourceTitleDate
exploit-dbPHP CGI Module 8.3.4 - Remote Code Execution (RCE)2025-06-15

References

→ the Explorer  ·  watch your stack  ·  NVD