CVE-2024-4577: PHP-CGI OS Command Injection Vulnerability. PHP,
PHP-CGI OS Command Injection Vulnerability. PHP, specifically Windows-based PHP used in CGI mode, contains an OS command injection vulnerability that allows for arbitrary code execution. This vulnerability is a patch bypass for CVE-2012-1823.
- CISA KEV-listed (remediation due 2024-07-03)
- used in ransomware campaigns
- EPSS 94.4% (100.0% percentile)