CVE-2024-4577
Argument Injection in PHP-CGI
Description
In PHP versions 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, when using Apache and PHP-CGI on Windows, if the system is set up to use certain code pages, Windows may use "Best-Fit" behavior to replace characters in command line given to Win32 API functions. PHP CGI module may misinterpret those characters as PHP options, which may allow a malicious user to pass options to PHP binary being run, and thus reveal the source code of scripts, run arbitrary PHP code on the server, etc.
In plain language
AI Act nowCVE-2024-4577 is a Windows-only PHP-CGI bug that lets an attacker take over a PHP web server or view hidden files with just network requests, and small businesses should treat it as urgent if you run PHP-CGI on Windows with Apache.
Unauthenticated remote attackers can exploit Windows text conversion (“Best-Fit” character mapping) when using Apache with PHP-CGI on Windows under specific non-UTF-8 locale/code page settings, causing PHP-CGI to misinterpret crafted characters as PHP options and enabling code execution and/or disclosure of server scripts; this is listed in CISA KEV and used in ransomware campaigns.
What to do now
- Check whether you run PHP-CGI on Windows with Apache (not just generic PHP-FPM) and whether your server’s locale/code pages use non-UTF-8 settings.
- Verify your PHP version and whether it is within the vulnerable ranges: 8.1 (before 8.1.29), 8.2 (before 8.2.20), or 8.3 (before 8.3.8).
- Upgrade PHP to one of the fixed versions: 8.1.29, 8.2.20, or 8.3.8 (or newer in the same branches).
- If you cannot upgrade immediately, disable or discontinue using PHP-CGI on Apache on the affected Windows setup and follow your vendor’s mitigation guidance until you can patch.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.
View exploit detailsAttack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
1 techniqueReferences
- Ботнет Evooo1Bot превращает зараженные устройства в проксиru-ru·Хакер (xakep.ru)· Exploited Alcatel ddos-botnet
- Evooo1Bot Linux Botnet Exploits Known Flaws to Turn Edge Devices Into SOCKS5 Proxiesen·The Hacker News· Exploited Alcatel OmniPCX Enterprise ddos-botnet
- Цепочка атаки на ИТ-инфраструктуру компании через AD CS: от CVE-2024-4577 до компрометации доменаru·Positive Technologies (Хабр)· Incident AD CS (ESC7) web-app
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2024-4577 and every CVE in our database. Create a free account — no credit card required.
Create Free Account