---
cve: "CVE-2024-4577"
severity: "CRITICAL"
cvss: 9.8
epss: "100%"
vendor: "PHP Group"
kev: true
exploited: true
published: "2024-06-09 20:15:09"
tags: [cve, security, critical]
source: tsecurity.de CVE-Dossier
exported: "2026-09-06T18:19:42+02:00"
---

# CVE-2024-4577

> 9.8 CRITICAL · ⚠️ CISA KEV (816 Tage) · 🔓 Exploited · 🧪 PoC

## Beschreibung

In PHP versions 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, when using Apache and PHP-CGI on Windows, if the system is set up to use certain code pages, Windows may use "Best-Fit" behavior to replace characters in command line given to Win32 API functions. PHP CGI module may misinterpret those characters as PHP options, which may allow a malicious user to pass options to PHP binary being run, and thus reveal the source code of scripts, run arbitrary PHP code on the server, etc.

## CVSS-Vektor

```
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Gering | bad |
| PR Privilegien | Keine | bad |
| UI Interaktion | Keine | bad |
| S Scope | Unverändert | good |
| C Vertraulichkeit | Hoch | bad |
| I Integrität | Hoch | bad |
| A Verfügbarkeit | Hoch | bad |

## Exploit-Evidenz

- [EDB-52331 — PHP CGI Module 8.3.4 - Remote Code Execution (RCE)](https://www.exploit-db.com/exploits/52331)

## Patch verfügbar (OSV)

- fc4973fb0dfae6085742868b8f0f05163e150a0c (Commit)
- 40298a988fca728ddc47316938da61e0f768c872 (Commit)

## Referenzen

- <https://github.com/php/php-src/security/advisories/GHSA-3qgc-jrrr-25jv>
- <https://blog.orange.tw/2024/06/cve-2024-4577-yet-another-php-rce.html>
- <https://devco.re/blog/2024/06/06/security-alert-cve-2024-4577-php-cgi-argument-injection-vulnerability-en/>
- <https://arstechnica.com/security/2024/06/php-vulnerability-allows-attackers-to-run-malicious-code-on-windows-servers/>
- <https://www.imperva.com/blog/imperva-protects-against-critical-php-vulnerability-cve-2024-4577/>
- <https://github.com/11whoami99/CVE-2024-4577>
- <https://github.com/xcanwin/CVE-2024-4577-PHP-RCE>
- <https://github.com/rapid7/metasploit-framework/pull/19247>
- <https://labs.watchtowr.com/no-way-php-strikes-again-cve-2024-4577/>
- <https://github.com/watchtowrlabs/CVE-2024-4577>
- <https://www.php.net/ChangeLog-8.php#8.1.29>
- <https://www.php.net/ChangeLog-8.php#8.2.20>
- <https://www.php.net/ChangeLog-8.php#8.3.8>
- <https://cert.be/en/advisory/warning-php-remote-code-execution-patch-immediately>
- <https://isc.sans.edu/diary/30994>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2024-4577) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
