Critical PHP Vulnerability CVE-2024-4577 Exploited
ID: dcb6a429-a570-5244-a390-67ef259555fc
STIX ID: report--dcb6a429-a570-5244-a390-67ef259555fc
Feed Name: Cyble Blog
Threat Score
This report describes CVE-2024-4577, a critical PHP CGI command/argument injection on Windows (CVSS 9.8) caused by character encoding "Best-Fit" conversions; a PoC was published and attackers quickly weaponized it to deliver TellYouThePass ransomware and scan systems (some activity linked to Muhstik). The advisory lists affected PHP versions, shows CGSI detections and IoCs (multiple IPs), and urges immediate patching to PHP 8.3.8/8.2.20/8.1.29 and regular security audits.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
