CVE-2024-4577

critical

Description

In PHP versions 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, when using Apache and PHP-CGI on Windows, if the system is set up to use certain code pages, Windows may use "Best-Fit" behavior to replace characters in command line given to Win32 API functions. PHP CGI module may misinterpret those characters as PHP options, which may allow a malicious user to pass options to PHP binary being run, and thus reveal the source code of scripts, run arbitrary PHP code on the server, etc.

From the Tenable Blog

CVE-2024-4577: Proof of Concept Available for PHP-CGI Argument Injection Vulnerability
CVE-2024-4577: Proof of Concept Available for PHP-CGI Argument Injection Vulnerability

Published: 2024-06-07

Researchers disclose a critical severity vulnerability affecting PHP installations and provide proof-of-concept exploit code, which could lead to remote code execution.

References

https://thehackernews.com/2026/08/evooo1bot-linux-botnet-exploits-known.html

https://storage.ghost.io/c/af/a0/afa04ee3-414f-4481-8d23-7e7c146f192e/content/files/2026/03/2025YiR-report.pdf

https://www.greynoise.io/blog/php-cryptomining-campaign

https://www.bleepingcomputer.com/news/security/lockbit-ransomware-gang-hacked-victim-negotiations-exposed/

https://thehackernews.com/2025/03/hackers-exploit-severe-php-flaw-to.html

https://blog.talosintelligence.com/patch-it-up-old-vulnerabilities-are-everyones-problems/

https://thehackernews.com/2025/03/cisa-adds-five-actively-exploited.html

https://www.greynoise.io/blog/mass-exploitation-critical-php-cgi-vulnerability-cve-2024-457

https://therecord.media/bug-affecting-php-scripts-global-issue

https://thehackernews.com/2025/03/php-cgi-rce-flaw-exploited-in-attacks.html

https://blog.talosintelligence.com/new-persistent-attacks-japan/

https://devco.re/blog/2025/01/09/worstfit-unveiling-hidden-transformers-in-windows-ansi/

https://blog.orange.tw/posts/2025-01-worstfit-unveiling-hidden-transformers-in-windows-ansi/

https://thehackernews.com/2025/01/mirai-botnet-variant-exploits-four.html

https://hackread.com/androxgh0st-botnet-iot-devices-exploit-vulnerabilities/

https://securelist.com/exploits-and-vulnerabilities-q3-2024/114839/

https://www.cloudsek.com/blog/mozi-resurfaces-as-androxgh0st-botnet-unraveling-the-latest-exploitation-wave

https://securelist.com/vulnerability-exploit-report-q2-2024/113455/

https://thehackernews.com/2024/08/hackers-exploit-php-vulnerability-to.html

https://symantec-enterprise-blogs.security.com/threat-intelligence/taiwan-malware-dns

https://www.akamai.com/blog/security-research/2024-php-exploit-cve-one-day-after-disclosure

https://github.com/khwajasaad267-coder/cve-2024-4577-lab

https://github.com/DuyDuongDuyDuong/CVE-2024-4577-Exploitation-AsyncRAT-Deployment-DFIR-Investigation

https://github.com/chengbochuan3/CVE-Web-Framework

https://github.com/DuyDuongDuyDuong/CVE-2024-4577-Exploitation-AsyncRAT-Deployment-DFIR-Investigatio

https://github.com/high-tech-r/quiet-cve

https://github.com/NKTriS/HTSOC

https://github.com/razureink/cve-2024-4577-phpcgi_rce_reproduction

https://github.com/Kanak-CypherX/cve-2024-4577-lab

https://github.com/Alpastx/CTFs

https://github.com/ykrishhh/cve-pocs

https://github.com/YAMRAJ13y/patchpilot

https://github.com/fDarkShadow/noctis

https://github.com/RENE155/cve-analize

https://github.com/SoWiEee/CVE-Research

https://github.com/gl1tch0x1/PHP_8.1.x_Exploit

https://github.com/AbdulMoiz6692/cve-vulnerability-scanner-pro

https://github.com/hermestoola/bb-hunter-pro

https://github.com/RehmanAjaz/CVE-Scanner

https://github.com/ZeroPathAI/zeropath-ctf

https://github.com/mystichackers/CVE-2025

https://github.com/seta-hoangbui/CVE_search

https://github.com/rayngnpc/CVE-2024-4577-rayng

https://github.com/NetHydra/RAW-CVE

https://github.com/carsxndev/php-cgi-argument-injection-detector

https://github.com/a1ex-var1amov/ctf-cve-2024-4577

https://github.com/InfoSec-DB/PHPCGIScanner

https://github.com/Ianthinus/CVE-2024-4577

https://github.com/Skycritch/CVE-2024-4577

https://github.com/r0otk3r/CVE-2024-4577

https://github.com/ibrahmsql/CVE-2024-4577

https://github.com/KimJuhyeong95/cve-2024-4577

https://github.com/tntrock/CVE-2024-4577_PowerShell

https://github.com/PuddinCat/GithubRepoSpider

https://github.com/Gill-Singh-A/CVE-2024-4577-Exploit

https://github.com/Night-have-dreams/php-cgi-Injector

https://github.com/Didarul342/CVE-2024-4577

https://github.com/mr-won/php-cgi-cve-2024-4577

https://github.com/nakataXmodem/cve-rce-poc

https://github.com/BTtea/CVE-2024-4577-RCE-PoC

https://github.com/ahmetramazank/CVE-2024-4577

https://github.com/proExploit1/cve

https://github.com/0xbd2/CVE-2024-4577

https://github.com/longhoangth18/CVE-2024-4577

https://github.com/JeninSutradhar/CVE-2024-4577-checker

https://github.com/AhmedMansour93/Event-ID-268-Rule-Name-SOC292-Possible-PHP-Injection-Detected-CVE-2024-4577-

https://github.com/ywChen-NTUST/PHP-CGI-RCE-Scanner

https://github.com/bughuntar/CVE-2024-4577

https://github.com/ManuelKy08/CVE-2024-4577---RR

https://github.com/Jcccccx/CVE-2024-4577

https://github.com/codeb0ss/CVEploiterv2

https://github.com/a-roshbaik/CVE-2024-4577-PHP-RCE

https://github.com/waived/CVE-2024-4577-PHP-RCE

https://github.com/ildefonso0/php-7.2.34-CVE-2024

https://github.com/cybersagor/CVE-2024-4577

https://github.com/charis3306/CVE-2024-4577

https://github.com/AlperenY-cs/CVE-2024-4577

https://github.com/olebris/CVE-2024-4577

https://github.com/ggfzx/CVE-2024-4577

https://github.com/PhinehasNarh/CVE-2024-4577-Defend

Details

Source: Mitre, NVD

Published: 2024-06-09

Updated: 2025-11-03

Named Vulnerability: WorstFitKnown Exploited Vulnerability (KEV)

Risk Information

CVSS v2

Base Score: 10

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

Severity: Critical

CVSS v3

Base Score: 9.8

Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Severity: Critical

EPSS

EPSS: 0.99987

Vulnerability Watch

Tenable Research has classified this CVE under the following Vulnerability Watch classification, which includes active and historical (inactive) classifications. You can learn more about these classifications on our blog.

Vulnerability of Interest