In PHP versions 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, when using Apache and PHP-CGI on Windows, if the system is set up to use certain code pages, Windows may use "Best-Fit" behavior to replace characters in command line given to Win32 API functions. PHP CGI module may misinterpret those characters as PHP options, which may allow a malicious user to pass options to PHP binary being run, and thus reveal the source code of scripts, run arbitrary PHP code on the server, etc.
Is CVE-2024-4577 exploited?
Listed in the CISA KEV catalog on 2024-06-12.
Federal remediation due 2024-07-03.
Past that date by 773 days.
Used in ransomware campaigns.
EPSS puts exploitation in the next 30 days at 100.0%.
Public exploit code: packaged in a public tool.
Public detection rules exist.
Which products and versions are affected?
No affected package list recorded here yet.
Is there a patch?
No patch identifier recorded here yet.
What PlainSec published about CVE-2024-4577
PlainSec has not published a story about this CVE.