logo

Ransomware Operators Exploit Critical PHP Vulnerability for RCE

ID: 2ca855fd-51e7-5a73-98ad-50dbb5170c2a

STIX ID: report--2ca855fd-51e7-5a73-98ad-50dbb5170c2a

Feed Name: Halcyon Blog

Threat Score
90/100

Date Published: 2025-03-12

Date Updated: 2026-04-28

...
...

**Executive summary:** CVE-2024-4577 is a critical (CVSS 9.8) PHP vulnerability affecting Windows Apache/php-cgi configurations that is being actively and widely exploited in the wild; attackers can perform argument injection via Unicode 'Best-Fit' conversion to execute code, escalate to SYSTEM privileges, modify registry keys, install scheduled tasks and malicious services (including use of Cobalt Strike 'TaoWu'), and ransomware groups began exploiting the flaw within days of disclosure—patches are available in PHP 8.1.29, 8.2.20, and 8.3.8 and should be deployed immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.