Vulnerability threat dossier

CVE-2024-4577

phpphp

In PHP versions 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, when using Apache and PHP-CGI on Windows, if the system is set up to use certain code pages, Windows may use "Best-Fit" behavior to replace characters in command line given to Win32 API functions. PHP CGI module may misinterpret those characters as PHP options, which may allow a malicious user to pass options to PHP binary being run, and thus reveal the source code of scripts, run arbitrary PHP code on the server, etc.

VTP deterministic threat59.5of 100 · CVSS excluded

VTP analyst assessment

PHP-CGI command injection on Windows

AI-assisted analytical recommendationDoes not set factual exploitation state
AI review stateCANDIDATE CREATED
AI priorityHIGH
AI confidence90%
Public exploitation · VTP factKEV

Assessment

CISA KEV lists CVE-2024-4577 as exploited globally, including known ransomware campaign use. On Windows Apache deployments using PHP-CGI and certain code pages, crafted characters can be interpreted as PHP options. This can let a remote attacker pass options to the PHP binary. Greenbone reports public exploit tooling coverage, but its tooling evidence does not establish successful execution.

Why it matters

  • PHP-CGI serves web requests, making the vulnerable parsing path reachable through crafted requests where the stated Windows, Apache, PHP-CGI, and code-page prerequisites apply.
  • The stated mechanism can give an attacker control over PHP options and may enable command injection.
  • CISA KEV status and known ransomware campaign use support prompt remediation for affected deployments.

Evidence

1 record references and 1 source references passed trusted post-response validation. The current deterministic record contains 0 independent evidence groups.

Uncertainties

The supplied exploit-tooling report does not establish exploit reliability or successful use against a particular deployment.

First-party honeypot request semantics are potentially consistent with this CVE. This is an unconfirmed candidate match, not proof of exploitation or successful execution.

Next watchpoint

If you use PHP-CGI with Apache on Windows, identify affected versions and code-page configurations, then update to PHP 8.1.29, 8.2.20, 8.3.8, or a later supported release.

AI baseline history (3)
  1. BASELINE ASSESSED
    PHP-CGI command injection on Windowsgpt-5.6-terra · low
  2. BASELINE ASSESSED
    Exploited PHP-CGI command injectiongpt-5.6-sol · high
  3. BASELINE ASSESSED
    PHP-CGI Windows command injectiongpt-5.6-sol · high
Technical severityCRITICALCVSS 9.8 · technical context
Public exploitationKEVGlobal public evidence
Exploit maturityPOCReliability not implied
EPSS1.00100th percentile · prediction
Evidence confidence90%Strongest independent active claim
VelocitySTABLEMaterial events only
First-party telemetryFirst-party honeypot request semantics are potentially consistent with this CVE. This is an unconfirmed candidate match, not proof of exploitation or successful execution.
Availability: SENSOR_ONLINE_NO_MATCHING_ACTIVITY · Evidence: UNKNOWN
HIGH

Honeypot request semantics are strongly consistent with CVE-2024-4577. This identifies likely attack intent, not successful exploitation or execution.

STRONGLY COMPATIBLETechnical consistency 95/100

Basis: deterministic technical candidate

Strongly consistent attempt; successful exploitation not observedDisclosure embargo completed
01

VTP deterministic assessment

Why this matters

  1. 01

    CISA KEV lists this vulnerability as known to be exploited globally.

  2. 02

    A proof of concept is reported; functional reliability is not established.

  3. 03

    EPSS is 1.00; this is predictive context, not exploitation evidence.

  4. 04

    First-party honeypot request semantics are potentially consistent with this CVE. This is an unconfirmed candidate match, not proof of exploitation or successful execution.

02

Material change ledger

What changed

EXPLOIT TEMPLATE AVAILABLEPublic exploit-oriented template available
KEV ADDEDCISA KEV entry added
03

Claim provenance

Evidence and source independence

2publications detected
2underlying evidence chains

0 primary sources · 0 dependent secondary reports · 1 reports with unresolved independence. Repetition remains visible without multiplying confirmation.

Source claimEXPLOIT TEMPLATE AVAILABLEPUBLIC EXPLOIT TEMPLATE
90%claim confidence
PRIMARYcorpus:OPENVAS_NASL:a8551b07b9ccadd0d3a962c0b3cbf2bea1ebb5caACTIVE
04

Event history

Threat timeline

  1. 02:3417 Sept
    EXPLOIT TEMPLATE AVAILABLE

    Public exploit-oriented template available

    Greenbone Community Feed published new or materially changed exploit-oriented tooling for this CVE. This is availability evidence, not evidence of exploitation in the wild.

  2. 00:0012 Jun
    KEV ADDED

    CISA KEV entry added

    CISA lists global known exploitation. This is not a VTP sensor observation.

05

Original publications

Source record

Exploit tooling coverage changed for 6 CVEs

Greenbone Community Feed recorded exploit-tooling coverage changes for 6 CVEs in this pinned revision. 6 have an active availability assertion for this revision. Tooling evidence does not establish exploitation in the wild or successful execution.

CVE-2020-7247CVE-2023-47218CVE-2024-2408CVE-2024-4577CVE-2024-5458CVE-2024-5585
Separate evidence group

Evooo1Bot Linux Botnet Exploits Known Flaws to Turn Edge Devices Into SOCKS5 Proxies

Cybersecurity researchers have flagged a previously undocumented Linux botnet family dubbed Evooo1Bot that derives its core functionality from the Mirai botnet source code and is equipped to turn internet-facing devices into SOCKS proxies. "While the malware reuses the DDoS engine from the publicly leaked Mirai source code, it extends the original framework with numerous capabilities, including

CVE-2007-3010CVE-2016-6277CVE-2018-14558CVE-2019-14931CVE-2020-10987CVE-2021-36260CVE-2021-46422CVE-2022-26134CVE-2022-29464CVE-2022-30525CVE-2022-37055CVE-2023-1389CVE-2024-10914CVE-2024-29269CVE-2024-4577CVE-2025-10123CVE-2025-1974CVE-2025-55583
Separate evidence group
Original
06

Technical vulnerability data

Context, not threat proof

VTP threat score59.5vtp-threat-v1-public
Public exploitation30 / 30
EPSS prediction20 / 20
Exploit availability7.5 / 15
Source independence0 / 15
Intelligence recency2 / 10
Threat acceleration0 / 10
CVSS technical severityExcluded
CVSS
9.8 · CRITICAL
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE
CWE-78
CPE records
4
Deterministic history records
20
Primary technical reference
07

Raw observations

First-party sensor records

First-party honeypot request semantics are potentially consistent with this CVE. This is an unconfirmed candidate match, not proof of exploitation or successful execution.