CVE-2024-4577: PHP-CGI OS Command Injection Vulnerability

Published Jun 6, 2024
·
Updated

Argument Injection in PHP-CGI

Other sources

Fixed bug (Bypass of CVE-2024-4577, Parameter Injection Vulnerability). (CVE-2024-8926)

PHP

In PHP versions 8.1. before 8.1.29, 8.2. before 8.2.20, 8.3. before 8.3.8, when using Apache and PHP-CGI on Windows, if the system is set up to use certain code pages, Windows may use "Best-Fit" behavior to replace characters in command line given to Win32 API functions. PHP CGI module may misinterpret those characters as PHP options, which may allow a malicious user to pass options to PHP binary being run, and thus reveal the source code of scripts, run arbitrary PHP code on the server, etc.

MITRE

PHP, specifically Windows-based PHP used in CGI mode, contains an OS command injection vulnerability that allows for arbitrary code execution. This vulnerability is a patch bypass for CVE-2012-1823.

CISA

Affected Software

15 affected componentsFixes available
PHP PHP<8.3.8
8.3.8
PHP PHP<8.1.29
8.1.29
PHP PHP<8.3.12
8.3.12
PHP Group PHP
All of the following
Any of the following
PHP PHP>=8.1.0<8.1.29
PHP PHP>=8.2.0<8.2.20
PHP PHP>=8.3.0<8.3.8
Microsoft Windows
Fedoraproject Fedora=39
Fedoraproject Fedora=40
Microsoft cbl2 php 8.1.28-1
Microsoft azl3 php 8.3.6-1
Microsoft cbl2 php 8.1.28-1
Microsoft azl3 php 8.3.8-1
Microsoft cbl2 php 8.1.29-1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade PHP to a version that resolves this vulnerability.

    Fixed in 8.3.8
  2. Upgrade

    Upgrade PHP to a version that resolves this vulnerability.

    Fixed in 8.1.29
  3. Upgrade

    Upgrade PHP to a version that resolves this vulnerability.

    Fixed in 8.3.12
  4. Upgrade

    Upgrade PHP-CGI (Windows) to a version that resolves this vulnerability.

    Fixed in 8.1.29
  5. Upgrade

    Upgrade PHP-CGI (Windows) to a version that resolves this vulnerability.

    Fixed in 8.2.20
  6. Upgrade

    Upgrade PHP-CGI (Windows) to a version that resolves this vulnerability.

    Fixed in 8.3.8
  7. Upgrade

    Upgrade to a fixed release to a version that resolves this vulnerability.

    Patch GHSA-3qgc-jrrr-25jv

Event History

Jun 6, 2024
CVE Published
via PHP·12:00 AM
Jun 7, 2024
News Published
via BleepingComputer·02:32 PM
News Published
via BleepingComputer·02:34 PM
Jun 9, 2024
CVE Published
via MITRE·07:42 PM
Data Sourced
via MITRE·07:42 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:15 PM
RemedyDescriptionSeverityWeaknessAffected Software
Jun 11, 2024
News Published
via BleepingComputer·02:25 PM
Jun 12, 2024
Known Exploited
via CISA·12:00 AM
Known Ransomware
via CISA·12:00 AM
News Published
via The Register·12:29 AM
News Published
via The Register·12:34 AM
Jun 30, 2024
Data Sourced
via Microsoft·02:00 PM
DescriptionSeverityWeakness
Data Sourced
via Microsoft·02:00 PM
Affected Software
Updated
via Microsoft·02:00 PM
Affected Software
Updated
via Microsoft·02:00 PM
SeverityAffected Software
Updated
via Microsoft·02:00 PM
DescriptionSeverity
Aug 20, 2024
News Published
via BleepingComputer·05:49 PM
Mar 11, 2025
News Published
via BleepingComputer·02:26 PM
May 8, 2025
News Published
via BleepingComputer·12:06 AM
Jun 15, 2025
Exploit Published
12:00 AM
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2024-4577?

CVE-2024-4577 is classified as a critical vulnerability affecting multiple PHP versions.

2

How do I fix CVE-2024-4577?

To fix CVE-2024-4577, upgrade PHP to versions 8.1.29, 8.2.20, or 8.3.8 or later.

3

Which versions of PHP are affected by CVE-2024-4577?

CVE-2024-4577 affects PHP versions 8.1.0 to 8.1.28, 8.2.0 to 8.2.19, and 8.3.0 to 8.3.7.

4

What is the impact of CVE-2024-4577?

The impact of CVE-2024-4577 includes potential parameter injection vulnerabilities leading to remote code execution.

5

Is CVE-2024-4577 present in Fedora 39 and 40?

Yes, CVE-2024-4577 can affect PHP installations in Fedora 39 and 40 that are running the vulnerable PHP versions.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203