Umbra Wiki cve cve/CVE-2024-4577
Back to wiki

CVE-2024-4577 — PHP-CGI OS Command Injection Vulnerability

provenance: imported · CVE: CVE-2024-4577

CVE-2024-4577: PHP-CGI OS Command Injection Vulnerability

CISA Known Exploited Vulnerability (KEV)

Vendor / project PHP Group
Product PHP
Date added 2024-06-12
Due date 2024-07-03
Ransomware campaign use Known

Description

PHP, specifically Windows-based PHP used in CGI mode, contains an OS command injection vulnerability that allows for arbitrary code execution. This vulnerability is a patch bypass for CVE-2012-1823.

Required action (CISA)

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Notes

This vulnerability affects a common open-source component, third-party library, or a protocol used by different products. Please check with specific vendors for information on patching status. For more information, please see: https://www.php.net/ChangeLog-8.php#; https://nvd.nist.gov/vuln/detail/CVE-2024-4577

References

  • NVD: https://nvd.nist.gov/vuln/detail/CVE-2024-4577
  • KEV catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog