Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2024-4577

99
FAUCET Score

CVE-2024-4577 is a critical PHP-CGI vulnerability affecting PHP versions 8.1.*, 8.2.*, and 8.3.* on Windows systems when used with Apache. This flaw allows attackers to inject arbitrary PHP options via character misinterpretation, leading to source code disclosure or arbitrary code execution. With a CVSS score of 9.8 (Critical), it presents a severe risk due to its network-based attack vector, low complexity, and complete compromise potential (Confidentiality, Integrity, Availability). The vulnerability is actively exploited in the wild, including by ransomware campaigns, with public exploit modules available and significant community discussion and media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
>= 8.1.0, < 8.1.29CPE matchmatch criteria
cpe:2.3:a:php:php:*:*:*:*:*:*:*:*
>= 8.2.0, < 8.2.20CPE matchmatch criteria
cpe:2.3:a:php:php:*:*:*:*:*:*:*:*
>= 8.3.0, < 8.3.8CPE matchmatch criteria
cpe:2.3:a:php:php:*:*:*:*:*:*:*:*
39CPE matchmatch criteria
cpe:2.3:o:fedoraproject:fedora:39:*:*:*:*:*:*:*
40CPE matchmatch criteria
cpe:2.3:o:fedoraproject:fedora:40:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

9.8CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
99.99%
Probability of exploitation in next 30 days
EPSS Percentile
100.0%
Percentile rank of EPSS score among Peer Group
As of 2026-07-24
Model: v2026.06.15
Added to KEV · Jun 12, 2024
Metasploit: PHP CGI Argument Injection Remote Code Execution · Jun 6, 2024
Nuclei: CVE-2024-4577 · Jun 7, 2024
ExploitDB: EDB-52331 · Jun 15, 2025
This CVE's current EPSS score of 0.9999 is in the 100th percentile among its peer group of 36,833 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (15)

github_advisorypatch availablevia nvd_reference
View patch
microsoftpatch availablevia msrc
Product: 17308-16823Fixed in: 8.1.29-1
microsoftpatch availablevia msrc
Product: 20015-17086Fixed in: 8.1.29-1
microsoftpatch availablevia msrc
Product: 17355-17086Fixed in: 8.1.29-1
microsoftpatch availablevia msrc
Product: 17719-17084Fixed in: 8.3.8-1
microsoftpatch availablevia msrc
Product: 17752-17084Fixed in: 8.3.8-1
microsoftpatch availablevia msrc
Product: azl3 php 8.3.6-1 on Azure Linux 3.0Fixed in: 8.3.8-1
microsoftpatch availablevia msrc
Product: cbl2 php 8.1.29-1 on CBL Mariner 2.0Fixed in: 8.1.29-1
microsoftpatch availablevia msrc
Product: cbl2 php 8.1.28-1 on CBL Mariner 2.0Fixed in: 8.1.29-1
microsoftpatch availablevia msrc
Product: azl3 php 8.3.8-1 on Azure Linux 3.0Fixed in: 8.3.8-1
nessuspatch availablevia llm_extracted
View patch
flaskvendor investigatingvia llm_extracted
hanwhavendor investigatingvia llm_extracted
mattermostvendor investigatingvia llm_extracted
mozillavendor investigatingvia llm_extracted

Vendor Advisories (11)

mattermostllm-mattermost-678aa097d34c6135CRITICAL

PHP CGI Module Argument Injection Vulnerability

Mar 19, 2025
mozillallm-mozilla-3e32d5899d202535CRITICAL

PHP CGI Module Argument Injection Vulnerability

Mar 19, 2025
hanwhallm-hanwha-de0c245a7cc7ac4dCRITICAL

PHP CGI Module Argument Injection Vulnerability

Mar 19, 2025
nessusllm-nessus-f1b84fec2927b9afCRITICAL

PHP CGI Module Argument Injection Vulnerability

Mar 19, 2025
flaskllm-flask-4ee44c1e8046a15eCRITICAL

PHP CGI Module Argument Injection Vulnerability

Mar 19, 2025
flaskllm-flask-037074f89b00355eCRITICAL

PHP Argument Injection Vulnerability Affecting Mitel Products

Jul 10, 2024
hanwhallm-hanwha-b3b9687e83666069CRITICAL

PHP Argument Injection Vulnerability Affecting Mitel Products

Jul 10, 2024
mozillallm-mozilla-f4df4d30890f56fcCRITICAL

PHP Argument Injection Vulnerability Affecting Mitel Products

Jul 10, 2024
mattermostllm-mattermost-a2366b9ba044a936CRITICAL

PHP Argument Injection Vulnerability Affecting Mitel Products

Jul 10, 2024
microsoft2024-Jun/CVE-2024-4577Critical

Argument Injection in PHP-CGI

Jun 11, 2024
redhatCVE-2024-4577Critical

php: Argument Injection in PHP-CGI

Jun 7, 2024

References

cisa.gov / known-exploited-vulnerabilities-catalog
US Government Resource
blog.talosintelligence.com / new-persistent-attacks-japan
ExploitThird Party Advisory
vicarius.io / vsociety/posts/php-cgi-argument-injection-to-rce-cve-2024-4577
ExploitThird Party Advisory
vicarius.io / vsociety/posts/php-cgi-os-command-injection-vulnerability-cve-2024-4577
ExploitThird Party Advisory
arstechnica.com / security/2024/06/php-vulnerability-allows-attackers-to-run-malicious-code-on-windows-servers
ExploitPress/Media CoverageThird Party Advisory
blog.orange.tw / 2024/06/cve-2024-4577-yet-another-php-rce.html
Third Party Advisory
cert.be / en/advisory/warning-php-remote-code-execution-patch-immediately
Third Party Advisory
devco.re / blog/2024/06/06/security-alert-cve-2024-4577-php-cgi-argument-injection-vulnerability-en
ExploitThird Party Advisory
github.com / 11whoami99/CVE-2024-4577
Exploit
github.com / php/php-src/security/advisories/GHSA-3qgc-jrrr-25jv
ExploitThird Party Advisory
github.com / rapid7/metasploit-framework/pull/19247
ExploitIssue TrackingPatch
github.com / watchtowrlabs/CVE-2024-4577
ExploitThird Party Advisory
github.com / xcanwin/CVE-2024-4577-PHP-RCE
ExploitThird Party Advisory
isc.sans.edu / diary/30994
ExploitThird Party Advisory
labs.watchtowr.com / no-way-php-strikes-again-cve-2024-4577
ExploitThird Party Advisory
lists.fedoraproject.org / archives/list/[email protected]/message/PKGTQUOA2NTZ3RXN22CSAUJPIRUYRB4B
Mailing List
lists.fedoraproject.org / archives/list/[email protected]/message/W45DBOH56NQDRTOM2DN2LNA2FZIMC3PK
Mailing List
security.netapp.com / advisory/ntap-20240621-0008
Third Party Advisory
imperva.com / blog/imperva-protects-against-critical-php-vulnerability-cve-2024-4577
Third Party Advisory
php.net / ChangeLog-8.php
Release Notes
php.net / ChangeLog-8.php
Release Notes
php.net / ChangeLog-8.php
Release Notes
openwall.com / lists/oss-security/2024/06/07/1
Mailing ListThird Party Advisory