Junglewise Threat Intelligence

CVE-2024-4577: PHP-CGI OS Command Injection Vulnerability

CVE-2024-4577 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2024-06-12

Technologies: PHP Group PHP. Vendors: PHP Group.

Executive brief

PHP-CGI on Windows contains an OS command injection vulnerability due to 'Best-Fit' character replacement in certain code pages. This allows remote attackers to bypass previous protections (CVE-2012-1823) and execute arbitrary PHP code or disclose source code by passing malicious options to the PHP binary.

Affected products

  • PHP Group PHP 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8

Timeline

  • 2024-06-06: disclosed: Initial security alert by DEVCORE
  • 2024-06-12: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2024-06-12: advisory: NVD publication date

Related threats