Skip to main content
CISA Known Exploited Vulnerabilities

PHP-CGI OS Command Injection Vulnerability is confirmed as actively exploited and is listed in the CISA KEV catalog.

Added to KEV
2024-06-12
Remediation due
2024-07-03
Ransomware
Known use

Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

CISA notes
This vulnerability affects a common open-source component, third-party library, or a protocol used by different products. Please check with specific vendors for information on patching status. For more information, please see: https://www.php.net/ChangeLog-8.php#; https://nvd.nist.gov/vuln/detail/CVE-2024-4577

Description

In PHP versions 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, when using Apache and PHP-CGI on Windows, if the system is set up to use certain code pages, Windows may use "Best-Fit" behavior to replace characters in command line given to Win32 API functions. PHP CGI module may misinterpret those characters as PHP options, which may allow a malicious user to pass options to PHP binary being run, and thus reveal the source code of scripts, run arbitrary PHP code on the server, etc.

Severity

CVSS 3.1 · CNA9.8 CRITICAL
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
SSVC · CISA-ADP
Exploitationactive
Automatableyes
Technical impacttotal

Affected Products

VendorProductAffected versions
PHP GroupPHP
8.1.* to <8.1.29
8.2.* to <8.2.20
8.3.* to <8.3.8

References

22 Links
Other references

Record Details

Published
2024-06-09
Last updated
2025-10-21
Assigner (CNA)
php
Credited to
Orange Tsai, DEVCORE Research Team

Related Tool Categories

Tool categories that test for or protect against this vulnerability class.

CVE record data © The MITRE Corporation, used under the CVE Terms of Use. Exploited-in-the-wild data from the CISA Known Exploited Vulnerabilities catalog (CC0). Exploit prediction scores by FIRST EPSS (first.org/epss). This site is not endorsed or certified by MITRE, NVD, CISA, or FIRST.