Critical PHP RCE vulnerability mass exploited in new attacks
A serious PHP remote code execution flaw that affects Windows PCs is currently being widely exploited, according to threat intelligence firm GreyNoise.
This PHP-CGI argument injection vulnerability, known as CVE-2024-4577, was fixed in June 2024 and impacts Windows PHP installations that have PHP operating in CGI mode. After successful exploitation, the system is completely compromised and unauthenticated attackers are able to run arbitrary code.
The Shadowserver Foundation reported seeing exploitation attempts, while WatchTowr Labs released proof-of-concept (PoC) exploit code the day after PHP maintainers published CVE-2024-4577 updates on June 7, 2024.
GreyNoise's warning follows Cisco Talos's earlier disclosure that, since at least early January 2025, an unidentified attacker ...

