logo

Critical PHP Vulnerability CVE-2024-4577 Exploited

ID: dcb6a429-a570-5244-a390-67ef259555fc

STIX ID: report--dcb6a429-a570-5244-a390-67ef259555fc

Feed Name: Cyble Blog

Threat Score
85/100

Date Published: 2024-10-24

Date Updated: 2026-07-17

...
...

This report describes CVE-2024-4577, a critical PHP CGI command/argument injection on Windows (CVSS 9.8) caused by character encoding "Best-Fit" conversions; a PoC was published and attackers quickly weaponized it to deliver TellYouThePass ransomware and scan systems (some activity linked to Muhstik). The advisory lists affected PHP versions, shows CGSI detections and IoCs (multiple IPs), and urges immediate patching to PHP 8.3.8/8.2.20/8.1.29 and regular security audits.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.