A AegiFlow
CRITICALCVSS 9.8KNOWN EXPLOITEDRANSOMWARE: KNOWN

CVE-2024-4577

CVE-2024-4577 updated by NVD

Published
2024-06-12
Modified
2026-09-21
Sources
cisa-kev, nvd

Summary

In PHP versions 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, when using Apache and PHP-CGI on Windows, if the system is set up to use certain code pages, Windows may use "Best-Fit" behavior to replace characters in command line given to Win32 API functions. PHP CGI module may misinterpret those characters as PHP options, which may allow a malicious user to pass options to PHP binary being run, and thus reveal the source code of scripts, run arbitrary PHP code on the server, etc.

Affected packages

EcosystemPackageAffected versionsFixed versions
PHPphp[object Object], [object Object], [object Object]

References

Includes data from the CISA Known Exploited Vulnerabilities catalog.

Includes data from the National Vulnerability Database (NIST). NVD data is in the public domain; this page is not endorsed by NIST.

CVE® is a registered trademark of The MITRE Corporation. CVE content reproduced under the CVE Terms of Use; copyright designation © MITRE.