Alexandre Daubois[verified]@alexdauboisPatch
The post describes a RCE vulnerability in Windows PHP‑CGI caused by soft‑hyphen character mapping, provides a CVSS score of 9.8, and notes that PHP versions 8.3.8, 8.2.20, and 8.1.29 contain the patch.
Alexandre Daubois[verified]@alexdauboisGeneral
The tweet clarifies the distinction between CWE and CVE, notes that CVE-2024-4577 has a patch, and identifies its weakness class (OS command injection), but it does not provide exploit details or active exploitation reports.
MAKHLOUF Med[verified]@CameleonGoodsPatch
The post is a warning urging PHP users on Windows to update immediately to the latest PHP releases to patch CVE‑2024‑4577, which allows remote code execution, but it contains no evidence of active attacks or exploit code.
DFIR Radar[verified]@DFIR_RadarActive Exploitation
The tweet reports an active attack campaign that exploits CVE‑2024‑4577, using PHP misconfigurations via HTTP POST, to deploy cryptomining malware from multiple regional IPs.
Lyrie.ai[verified]@lyrie_aiDisclosure
The tweet announces the discovery of CVE-2024-4577, a PHP-CGI remote code execution vulnerability triggered by Windows Best‑Fit Character Conversion. No proof of concept, exploit tool, or mitigation information is included.
MAKHLOUF Med[verified]@CameleonGoodsActive Exploitation
CVE-2024-4577 is a remote command‑execution flaw in PHP CGI on Windows, being actively exploited; immediate patching to the latest secure PHP releases is urged.
MAKHLOUF Med[verified]@CameleonGoodsPatch
A Moroccan security advisory (ma-CERT) warns that CVE-2024-4577 allows remote code execution on PHP for Windows and urges users to apply the latest PHP security updates immediately, with no evidence of active exploitation or PoC.
Aviatrix Threat Research Center[verified]@aviatrixtrcActive Exploitation
CVE-2024-4577 is being actively exploited by the RedTail cryptomining campaign to gain remote code execution, deploy miners, and establish C2 connections; no PoC, patch, or exploit code is disclosed.