logo

PHP fixes critical RCE flaw impacting all versions for Windows

ID: f054548a-e3a7-5124-bf06-03be971086ce

STIX ID: report--f054548a-e3a7-5124-bf06-03be971086ce

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2024-06-07

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

A critical PHP for Windows remote code execution vulnerability (CVE-2024-4577) was disclosed affecting all PHP for Windows releases due to Windows 'Best-Fit' encoding conversion behavior that enables unauthenticated CGI argument injection. Patches have been released for supported versions (PHP 8.3.8, 8.2.20, 8.1.29); mitigations for unpatched or EoL installations include mod_rewrite blocking rules, removing CGI ScriptAlias in XAMPP, and migrating to FastCGI/PHP-FPM/Mod-PHP. Active scanning for vulnerable servers has already been observed.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.