logo

What’s Going on With CVE-2024-4577 (Critical RCE in PHP)?

ID: 2fee47b3-94ac-5f80-a01e-266005366bf3

STIX ID: report--2fee47b3-94ac-5f80-a01e-266005366bf3

Feed Name: GreyNoise Labs

Threat Score
78/100

Date Published: 2024-06-13

Date Updated: 2026-04-27

Author: Konstantin Lazarev

...
...

This blog post analyzes active exploitation of CVE-2024-4577 (a Windows PHP-CGI argument-injection RCE), showing multiple real-world payloads and confirmed RCE attempts that fetched and executed Cobalt Strike beacons and Gh0st RAT variants; the report provides payload examples, observed source IPs/domains/URLs, and attacker TTPs (certutil, PowerShell, php://input auto_prepend_file), while noting limited overall exposure (scans indicate ~0.5% of XAMPP hosts vulnerable).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.