CVE-2024-4577

CVE-2024-4577 is a critical-severity vulnerability in Php with a CVSS 3.x base score of 9.8. It is listed in CISA's Known Exploited Vulnerabilities (KEV) catalog, confirming it has been exploited in the wild (added 2024-06-12). The underlying weakness is classified as CWE-78.

Key facts

Description

In PHP versions 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, when using Apache and PHP-CGI on Windows, if the system is set up to use certain code pages, Windows may use "Best-Fit" behavior to replace characters in command line given to Win32 API functions. PHP CGI module may misinterpret those characters as PHP options, which may allow a malicious user to pass options to PHP binary being run, and thus reveal the source code of scripts, run arbitrary PHP code on the server, etc.

Frequently asked questions

What is CVE-2024-4577?
In PHP versions 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, when using Apache and PHP-CGI on Windows, if the system is set up to use certain code pages, Windows may use "Best-Fit" behavior to replace characters in command line given to Win32 API functions. PHP CGI module may misinterpret those characters as PHP options, which may allow a malicious user to pass options to PHP binary being run, and thus reveal the source code of scripts, run arbitrary PHP code on the server, etc.
How severe is CVE-2024-4577?
CVE-2024-4577 has a CVSS 3.x base score of 9.8, rated critical severity. It is exploitable over network with low attack complexity, requires no privileges and no user interaction. Impact on confidentiality is high, integrity high, and availability high.
Is CVE-2024-4577 being actively exploited?
Yes. CVE-2024-4577 is on CISA's Known Exploited Vulnerabilities (KEV) catalog, added on 2024-06-12, which means active exploitation has been confirmed. It should be prioritised for remediation.
What products are affected by CVE-2024-4577?
CVE-2024-4577 primarily affects Php. In total, 3 product configurations (CPEs) are listed as vulnerable; see the affected-products list for the exact versions.
How do I fix CVE-2024-4577?
Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Because this CVE is known to be actively exploited, treat remediation as urgent — CISA KEV typically sets a short remediation deadline.
Does CVE-2024-4577 have an EU (EUVD) identifier?
Yes. CVE-2024-4577 is tracked in the ENISA EU Vulnerability Database (EUVD) as EUVD-2024-44188. It is also flagged as exploited in the EUVD (since 2024-06-12).
When was CVE-2024-4577 published?
CVE-2024-4577 was published on 2024-06-09 and last updated on 2026-06-17.

References

Affected products (3)

More vulnerabilities in Php

All CVEs affecting Php →

Other CWE-78 (OS Command Injection) vulnerabilities

Browse all CWE-78 (OS Command Injection) vulnerabilities →

Threat intelligence

Threat-intel indicators referencing this CVE: