Threat intelligence company GreyNoise warns that a critical PHP remote code execution vulnerability that impacts Windows systems is now under mass exploitation. Tracked as CVE-2024-4577, this PHP-CGI argument injection flaw was patched in June 2024 and affects Windows PHP installations with PHP running in CGI mode. Successful exploitation enables unauthenticated attackers to execute arbitrary code and leads to complete system compromise following successful exploitation. A day after PHP maintainers released CVE-2024-4577 patches on June 7, 2024, WatchTowr Labs released proof-of-concept (PoC) exploit code, and the Shadowserver Foundation reported observing exploitation attempts. GreyNoise's warning comes after Cisco Talos revealed earlier that an unknown attacker had exploited the same PHP vulnerability to target Japanese organizations since at least early January 2025. While Talos observed the attackers attempting to steal credentials, it believes their goals extend beyond just credential harvesting, based on post-exploitation activities, which include establishing persistence, elevating privileges to SYSTEM level, deployment of adversarial tools and frameworks, and usage of "TaoWu" Cobalt Strike kit plugins. However, as GreyNoise reported, the threat actors behind this malicious activity cast a much wider net by targeting vulnerable devices globally, with significant increases observed in the United States, Singapore, Japan, and other countries since January 2025. In Januar...
Critical PHP RCE vulnerability mass exploited in new attacks
BleepingComputer
·Sergiu Gatlan
·Published Mar 11, 2025
·Updated
Affected Software
2 affected components
PHP PHP
The PHP Group PHP
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses a critical PHP remote code execution vulnerability, identified as CVE-2024-4577, that is currently being mass exploited.
2
What security implications are discussed in the article?
The article highlights the threat of mass exploitation of the PHP vulnerability, potentially leading to unauthorized remote code execution on affected systems.
3
What products or software are affected by this vulnerability?
The vulnerability affects PHP installations, particularly under Windows systems, including software developed by The PHP Group.
4
Who reported the critical PHP vulnerability and its exploitation?
The critical vulnerability and its ongoing exploitation were reported by the threat intelligence company GreyNoise.
5
When was this PHP vulnerability patched?
The article notes that the PHP remote code execution flaw was patched, but does not specify the exact date of the patch.