← Vulnerability feed

Vulnerability record · CVE-2024-4577 · published 9 June 2024

CVE-2024-4577: PHP-CGI on Windows argument injection leads to remote code execution

Php · Php

PHP-CGI on Windows can misinterpret characters in the command line passed to Win32 API functions when certain code pages are configured, due to Windows "Best-Fit" character replacement. This lets an attacker inject PHP options into the running PHP binary, exposing source code or executing arbitrary PHP code. It matters because the affected component is widely deployed and the flaw is trivially reachable over the network without credentials.

9.8 CVSS 3.1 Critical CISA KEV since 12 Jun 2024 Known ransomware use EPSS 100% · top 0.1% CWE-78 · OS command injection
9.8CVSS 3.1 base score
100%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
2Affected product versions listed by NVD
42References, 21 tagged exploit
17 Jun 2026Last modified by NVD

Description

In PHP versions 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, when using Apache and PHP-CGI on Windows, if the system is set up to use certain code pages, Windows may use "Best-Fit" behavior to replace characters in command line given to Win32 API functions. PHP CGI module may misinterpret those characters as PHP options, which may allow a malicious user to pass options to PHP binary being run, and thus reveal the source code of scripts, run arbitrary PHP code on the server, etc.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 16 September 2026. Confidence: high.

critical priorityUnauthenticated network-reachable RCE with a CVSS of 9.8, KEV listing with known ransomware use, and near-certain EPSS probability.

What it is

PHP-CGI on Windows can misinterpret characters in the command line passed to Win32 API functions when certain code pages are configured, due to Windows "Best-Fit" character replacement. This lets an attacker inject PHP options into the running PHP binary, exposing source code or executing arbitrary PHP code. It matters because the affected component is widely deployed and the flaw is trivially reachable over the network without credentials.

Impact

An unauthenticated attacker can run arbitrary PHP code on the server, read script source code, and potentially pivot to full host compromise under the web server's privileges.

Attack surface

Reached remotely over HTTP against a Windows host running Apache with PHP-CGI in a vulnerable configuration; no authentication or user interaction is required per the CVSS vector (AV:N/AC:L/PR:N/UI:N).

Exploitation

CISA added it to KEV on 2024-06-12 with a 2024-07-03 due date and flags known ransomware campaign use; EPSS 30-day probability is 0.99987 (99.983rd percentile), and multiple references carry the Exploit tag including Metasploit and public PoCs.

What to do

  • Upgrade PHP to 8.1.29, 8.2.20, 8.3.8 or later on affected Windows hosts.
  • If patching is not immediately possible, migrate from PHP-CGI to PHP-FPM or another SAPI, or disable the CGI handler.
  • Apply vendor mitigations per CISA KEV guidance or discontinue use of the affected configuration.
  • Restrict network exposure of PHP-CGI endpoints and review Windows code page settings on affected servers.

Detection

  • Monitor web server and PHP-CGI logs for requests containing encoded or unusual characters (e.g. %AD, soft hyphen variants) in query strings or paths.
  • Alert on unexpected PHP process creation or child processes spawned by the web server on Windows hosts.
  • Hunt for outbound connections or file writes originating from the web server process that deviate from baseline.
  • Correlate with CISA KEV due-date tracking to confirm remediation of exposed instances.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2024-4577 to the Known Exploited Vulnerabilities catalog on 12 June 2024 as "PHP-CGI OS Command Injection Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 3 July 2024.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://www.openwall.com/lists/oss-security/2024/06/07/1 Mailing ListThird Party Advisory
https://arstechnica.com/security/2024/06/php-vulnerability-allows-attackers-to-run-malicious-code-on-windows-servers/ ExploitPress/Media CoverageThird Party Advisory
https://blog.orange.tw/2024/06/cve-2024-4577-yet-another-php-rce.html Third Party Advisory
https://cert.be/en/advisory/warning-php-remote-code-execution-patch-immediately Third Party Advisory
https://devco.re/blog/2024/06/06/security-alert-cve-2024-4577-php-cgi-argument-injection-vulnerability-en/ ExploitThird Party Advisory
https://github.com/11whoami99/CVE-2024-4577 Exploit
https://github.com/php/php-src/security/advisories/GHSA-3qgc-jrrr-25jv ExploitThird Party Advisory
https://github.com/rapid7/metasploit-framework/pull/19247 ExploitIssue TrackingPatch
https://github.com/watchtowrlabs/CVE-2024-4577 ExploitThird Party Advisory
https://github.com/xcanwin/CVE-2024-4577-PHP-RCE ExploitThird Party Advisory
https://isc.sans.edu/diary/30994 ExploitThird Party Advisory
https://labs.watchtowr.com/no-way-php-strikes-again-cve-2024-4577/ ExploitThird Party Advisory
https://lists.fedoraproject.org/archives/list/[email protected]/message/PKGTQUOA2NTZ3RXN22CSAUJPI Mailing List
https://lists.fedoraproject.org/archives/list/[email protected]/message/W45DBOH56NQDRTOM2DN2LNA2F Mailing List
https://security.netapp.com/advisory/ntap-20240621-0008/ Third Party Advisory
https://www.imperva.com/blog/imperva-protects-against-critical-php-vulnerability-cve-2024-4577/ Third Party Advisory
https://www.php.net/ChangeLog-8.php#8.1.29 Release Notes
https://www.php.net/ChangeLog-8.php#8.2.20 Release Notes
https://www.php.net/ChangeLog-8.php#8.3.8 Release Notes
http://www.openwall.com/lists/oss-security/2024/06/07/1 Mailing ListThird Party Advisory
https://arstechnica.com/security/2024/06/php-vulnerability-allows-attackers-to-run-malicious-code-on-windows-servers/ ExploitPress/Media CoverageThird Party Advisory
https://blog.orange.tw/2024/06/cve-2024-4577-yet-another-php-rce.html Third Party Advisory
https://blog.talosintelligence.com/new-persistent-attacks-japan/ ExploitThird Party Advisory
https://cert.be/en/advisory/warning-php-remote-code-execution-patch-immediately Third Party Advisory
https://devco.re/blog/2024/06/06/security-alert-cve-2024-4577-php-cgi-argument-injection-vulnerability-en/ ExploitThird Party Advisory
https://github.com/11whoami99/CVE-2024-4577 Exploit
https://github.com/php/php-src/security/advisories/GHSA-3qgc-jrrr-25jv ExploitThird Party Advisory
https://github.com/rapid7/metasploit-framework/pull/19247 ExploitIssue TrackingPatch
https://github.com/watchtowrlabs/CVE-2024-4577 ExploitThird Party Advisory
https://github.com/xcanwin/CVE-2024-4577-PHP-RCE ExploitThird Party Advisory
https://isc.sans.edu/diary/30994 ExploitThird Party Advisory
https://labs.watchtowr.com/no-way-php-strikes-again-cve-2024-4577/ ExploitThird Party Advisory
https://lists.fedoraproject.org/archives/list/[email protected]/message/PKGTQUOA2NTZ3RXN22CSAUJPI Mailing List
https://lists.fedoraproject.org/archives/list/[email protected]/message/W45DBOH56NQDRTOM2DN2LNA2F Mailing List
https://security.netapp.com/advisory/ntap-20240621-0008/ Third Party Advisory
https://www.imperva.com/blog/imperva-protects-against-critical-php-vulnerability-cve-2024-4577/ Third Party Advisory
https://www.php.net/ChangeLog-8.php#8.1.29 Release Notes
https://www.php.net/ChangeLog-8.php#8.2.20 Release Notes
https://www.php.net/ChangeLog-8.php#8.3.8 Release Notes
https://www.vicarius.io/vsociety/posts/php-cgi-argument-injection-to-rce-cve-2024-4577 ExploitThird Party Advisory

Track CVE-2024-4577 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2021-44228Apache Log4j2 JNDI lookup remote code executionApache Log4j2 versions 2.0-beta9 through 2.15.0 (excluding 2.12.2, 2.12.3, and 2.3.1) do not protect against attacker-controlled LDAP and other JNDI …KEVEPSS 100%analysed9.8CVE-2021-44026Roundcube Webmail SQL injection via search parametersRoundcube Webmail before 1.3.17 and 1.4.x before 1.4.12 is prone to SQL injection through the search or search_params input. The flaw is remotely rea…KEVEPSS 70%analysed9.8CVE-2021-42013Apache HTTP Server path traversal and RCE via incomplete fixThe fix for CVE-2021-41773 in Apache HTTP Server 2.4.50 was insufficient, leaving a path traversal flaw that lets attackers map URLs to files outside…KEVEPSS 100%analysed9.8CVE-2021-41773Apache HTTP Server 2.4.49 path traversal and RCEA path normalization flaw introduced in Apache HTTP Server 2.4.49 lets attackers map URLs to files outside directories configured by Alias-like direc…KEVEPSS 100%analysed9.8CVE-2021-1870Apple WebKit logic flaw allows remote code executionA logic issue in Apple's WebKit was addressed with improved restrictions, affecting macOS Big Sur, Catalina, Mojave, iOS and iPadOS, plus WebKitGTK a…KEVEPSS 7.7%analysed9.8CVE-2021-1871Apple WebKit logic flaw allows remote code executionA logic issue in Apple's WebKit was addressed with improved restrictions. It affects macOS Big Sur, Catalina, Mojave, iOS and iPadOS, and a remote at…KEVEPSS 7.0%analysed9.8CVE-2020-16846SaltStack Salt API shell injection via crafted web requestsSaltStack Salt through 3002 is vulnerable to OS command injection when the SSH client is enabled and crafted web requests are sent to the Salt API. T…KEVEPSS 100%analysed9.8CVE-2020-1938Apache Tomcat AJP connector file read and JSP execution flawApache Tomcat shipped an AJP Connector enabled by default that listened on all configured IP addresses, and Tomcat treats AJP connections as more tru…KEVEPSS 99%analysed

Source: NIST National Vulnerability Database (record CVE-2024-4577), CISA KEV, FIRST EPSS (scores of 2026-09-20). This page is refreshed as NVD updates the record.