Vulnerability record · CVE-2024-4577 · published 9 June 2024
CVE-2024-4577: PHP-CGI on Windows argument injection leads to remote code execution
Php · Php
PHP-CGI on Windows can misinterpret characters in the command line passed to Win32 API functions when certain code pages are configured, due to Windows "Best-Fit" character replacement. This lets an attacker inject PHP options into the running PHP binary, exposing source code or executing arbitrary PHP code. It matters because the affected component is widely deployed and the flaw is trivially reachable over the network without credentials.
Description
In PHP versions 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, when using Apache and PHP-CGI on Windows, if the system is set up to use certain code pages, Windows may use "Best-Fit" behavior to replace characters in command line given to Win32 API functions. PHP CGI module may misinterpret those characters as PHP options, which may allow a malicious user to pass options to PHP binary being run, and thus reveal the source code of scripts, run arbitrary PHP code on the server, etc.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated network-reachable RCE with a CVSS of 9.8, KEV listing with known ransomware use, and near-certain EPSS probability.
What it is
PHP-CGI on Windows can misinterpret characters in the command line passed to Win32 API functions when certain code pages are configured, due to Windows "Best-Fit" character replacement. This lets an attacker inject PHP options into the running PHP binary, exposing source code or executing arbitrary PHP code. It matters because the affected component is widely deployed and the flaw is trivially reachable over the network without credentials.
Impact
An unauthenticated attacker can run arbitrary PHP code on the server, read script source code, and potentially pivot to full host compromise under the web server's privileges.
Attack surface
Reached remotely over HTTP against a Windows host running Apache with PHP-CGI in a vulnerable configuration; no authentication or user interaction is required per the CVSS vector (AV:N/AC:L/PR:N/UI:N).
Exploitation
CISA added it to KEV on 2024-06-12 with a 2024-07-03 due date and flags known ransomware campaign use; EPSS 30-day probability is 0.99987 (99.983rd percentile), and multiple references carry the Exploit tag including Metasploit and public PoCs.
What to do
- Upgrade PHP to 8.1.29, 8.2.20, 8.3.8 or later on affected Windows hosts.
- If patching is not immediately possible, migrate from PHP-CGI to PHP-FPM or another SAPI, or disable the CGI handler.
- Apply vendor mitigations per CISA KEV guidance or discontinue use of the affected configuration.
- Restrict network exposure of PHP-CGI endpoints and review Windows code page settings on affected servers.
Detection
- Monitor web server and PHP-CGI logs for requests containing encoded or unusual characters (e.g. %AD, soft hyphen variants) in query strings or paths.
- Alert on unexpected PHP process creation or child processes spawned by the web server on Windows hosts.
- Hunt for outbound connections or file writes originating from the web server process that deviate from baseline.
- Correlate with CISA KEV due-date tracking to confirm remediation of exposed instances.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2024-4577 to the Known Exploited Vulnerabilities catalog on 12 June 2024 as "PHP-CGI OS Command Injection Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 3 July 2024.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2024-4577 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2024-4577), CISA KEV, FIRST EPSS (scores of 2026-09-20). This page is refreshed as NVD updates the record.