CVE record
CVE-2024-4577
PHP-CGI OS Command Injection Vulnerability
PHP, specifically Windows-based PHP used in CGI mode, contains an OS command injection vulnerability that allows for arbitrary code execution. This vulnerability is a patch bypass for CVE-2012-1823.
CVE evidence
Known exploitation
Listed in CISA KEV
Absence from the fetched catalog does not establish that exploitation has not occurred.
Severity
critical
CVSS 9.8 ยท CVSS_V3
Affected packages
0
Supported package records returned by OSV. Vendor and product names are not used to infer matches.
CISA Known Exploited Vulnerabilities
Catalog record
- Vendor / project
- PHP Group
- Product
- PHP
- Date added
- Jun 12, 2024
- CISA federal remediation due date
- Jul 3, 2024
- Required action
- Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
- Known ransomware campaign use
- Known
- CWE
- CWE-78
OSV package mapping
Affected open-source packages
OSV did not return a package mapping in the five supported ecosystems. RequestGuard does not infer package names from the CISA vendor or product fields.