CVE-2024-4577Active Exploitation(fedoraproject / fedora)

CRITICALCVSS 9.8 · CRITICALCISA KEV

Exploitation observed; activity peaked at 9 mentions and remains active

Immediate actions

  • Patch fedoraproject fedora systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

In PHP versions 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, when using Apache and PHP-CGI on Windows, if the system is set up to use certain code pages, Windows may use "Best-Fit" behavior to replace characters in command line given to Win32 API functions. PHP CGI module may misinterpret those characters as PHP options, which may allow a malicious user to pass options to PHP binary being run, and thus reveal the source code of scripts, run arbitrary PHP code on the server, etc.

8.3/ 10 priority

Sources & remediation

Listed in the CISA Known Exploited Vulnerabilities catalog. Federal remediation due date: 2024-07-03. Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Weakness type (CWE)
CWE-78

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • fedora
  • php
  • windows

Threat summary

  • Active exploitation appears in 6 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 23 mentions across 12 observed days

What's happening

  • Active exploitation reported across 6 signals
  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 6 signals
  • Technical details provided in 16 signals
  • General: 6 classified signals
  • Disclosure: 6 classified signals
  • Peaked 7d ago at 9 mentions (2026-04-29); latest day: 2
  • 23 total mentions across 12 days

Affected systems

Products
fedoraphpwindows

3 versions affected across 3 products

Deep dive

Activity timeline23 mentions / 12d
02579Mentions · 2026-02-11: 1Mentions · 2026-03-09: 1Mentions · 2026-03-29: 1Mentions · 2026-03-30: 1Mentions · 2026-04-29: 9Mentions · 2026-04-30: 2Mentions · 2026-05-11: 1Mentions · 2026-06-13: 2Mentions · 2026-06-15: 1Mentions · 2026-06-21: 1Mentions · 2026-08-02: 1Mentions · 2026-09-11: 2PoC Mentioned / Linked · 2026-09-11: 1Exploit Tool / Code · 2026-09-11: 1Active Exploitation · 2026-02-11: 1Active Exploitation · 2026-04-29: 1Active Exploitation · 2026-04-30: 2Active Exploitation · 2026-05-11: 1Active Exploitation · 2026-06-15: 1Patch / Workaround · 2026-03-09: 1Patch / Workaround · 2026-06-13: 2Patch / Workaround · 2026-06-15: 1Patch / Workaround · 2026-06-21: 1Patch / Workaround · 2026-08-02: 1Technical Details · 2026-03-09: 1Technical Details · 2026-03-30: 1Technical Details · 2026-04-29: 7Technical Details · 2026-04-30: 2Technical Details · 2026-06-13: 2Technical Details · 2026-06-15: 1Technical Details · 2026-06-21: 1Technical Details · 2026-08-02: 102-1103-0903-2903-3004-2904-3005-1106-1306-1506-2108-0209-11
Signal classification5 categories
Active Exploitation
626.1%
General
626.1%
Disclosure
626.1%
Patch
417.4%
Exploit
14.3%
Referenced assets6 URLs
Classification over time
DateTotalLabels
2026-02-111
Active Exploitation1
2026-03-091
Patch1
2026-03-291
General1
2026-03-301
General1
2026-04-299
Active Exploitation1Disclosure6General2
2026-04-302
Active Exploitation2
2026-05-111
Active Exploitation1
2026-06-132
Patch2
2026-06-151
Active Exploitation1
2026-06-211
Patch1
2026-08-021
General1
2026-09-112
Exploit1General1
Full discourse20 posts
  • Alexandre Daubois@alexdaubois
    Patch

    CVE-2024-4577: millions of Windows PHP-CGI servers were one HTTP request away from RCE. Exceptional CVSS of 9.8. 😬 Windows in code pages like zh/ja does "Best-Fit" mapping on cmdline args. A soft hyphen (0xAD) becomes a real "-" before PHP-CGI ever sees its argv. A URL with 0xAD-prefixed bytes slipped past PHP's argument filter and reached php-cgi.exe as -d allow_url_include=1 -d auto_prepend_file=php://input. Inject any code via POST body. Patched in #PHP 8.3.8 / 8.2.20 / 8.1.29.

    Post summary

    The post describes a RCE vulnerability in Windows PHP‑CGI caused by soft‑hyphen character mapping, provides a CVSS score of 9.8, and notes that PHP versions 8.3.8, 8.2.20, and 8.1.29 contain the patch.

    0402791.6K
    1.7K followersView on X
  • Alexandre Daubois@alexdaubois
    General

    A #CWE is not a CVE, and swapping the two is the fastest way to lose a security conversation. 🔐 CVE-2024-4577 is one vulnerability: one product, specific versions, a patch. CWE-78 is the WEAKNESS class it belongs to, OS command injection, and it has no version and no patch. One CWE is the root cause of thousands of CVEs. That's why the CWE Top 25 reads like a code review checklist while the CVE feed reads like a queue. 2025 Top 25 opens on CWE-79, CWE-89, CWE-352. XSS, SQL injection, CSRF. Still.

    Post summary

    The tweet clarifies the distinction between CWE and CVE, notes that CVE-2024-4577 has a patch, and identifies its weakness class (OS command injection), but it does not provide exploit details or active exploitation reports.

    1101221.2K
    1.7K followersView on X
  • MAKHLOUF Med@CameleonGoods
    Patch

    تحذير أمني خطير لمستخدمي PHP على أنظمة ويندوز. تم اكتشاف ثغرة (CVE-2024-4577) تسمح للمهاجمين بتنفيذ تعليمات برمجية عن بعد والسيطرة على الخادم، خاصة في بيئات مثل XAMPP. الفائدة من التحديث الفوري هي حماية الخوادم من الاختراق ومنع الهجمات التي تستغل هذه الثغرة لتجاوز إجراءات الحماية السابقة. الحل هو التحديث فوراً إلى أحدث إصدارات PHP (8.3.8, 8.2.20, 8.1.29). شارك هذا التحذير لحماية المطورين الآخرين. #أمن_سيبراني #PHP #Windows #ثغرة_أمنية

    Post summary

    The post is a warning urging PHP users on Windows to update immediately to the latest PHP releases to patch CVE‑2024‑4577, which allows remote code execution, but it contains no evidence of active attacks or exploit code.

    00040104
    1.1K followersView on X
  • DFIR Radar@DFIR_Radar
    Active Exploitation

    New Libredtail campaign exploits CVE-2024-4577 to deploy redtail cryptomining malware via HTTP POST attacks targeting PHP misconfigurations. Honeypot data shows coordinated activity from German 🇩🇪, British 🇬🇧, and Indian 🇮🇳 IPs. #DFIR_Radar https://t.co/t0uLDWZUB7

    Post summary

    The tweet reports an active attack campaign that exploits CVE‑2024‑4577, using PHP misconfigurations via HTTP POST, to deploy cryptomining malware from multiple regional IPs.

    10010122
    1.4K followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    00:14 UTC: Thread live on @lyrie_ai. CVE-2024-4577: PHP-CGI RCE via Windows Best-Fit Character Conversion

    Post summary

    The tweet announces the discovery of CVE-2024-4577, a PHP-CGI remote code execution vulnerability triggered by Windows Best‑Fit Character Conversion. No proof of concept, exploit tool, or mitigation information is included.

    2000045
    125 followersView on X
  • Koupon@Shabosec
    General

    @jesuz_boi @v3n0m30 @H4ckmanac Confirm Suya as long you have the CVE-2024-4577 You’re in swiftly 😋😋😋😋

    Post summary

    The tweet references CVE‑2024‑4577 but offers no further detail about the vulnerability or its exploitation.

    1001060
    946 followersView on X
  • ExploitGrid@exploitgrid
    Exploit

    [EXPLOIT] CVE-2024-4577 [CRITICAL/PoC] edu-recon 🔗 https://exploitgrid.net/exploits/e1f6e85e-f9f3-4d7c-9a71-295a3a65190a

    Post summary

    The post announces a critical PoC and functional exploit for CVE‑2024‑4577, providing a link to exploit code, but lacks details on active exploitation or available patches.

    1000041
    42 followersView on X
  • ExploitGrid@exploitgrid
    General

    🛡️ #ExploitGrid Daily #Threat Digest Critical Exploits disclosed today: CVE-2018-20062 CVE-2023-25157 CVE-2024-4577 CVE-2026-20253 CVE-2026-41096 ..🧵👇

    Post summary

    The tweet merely lists five newly disclosed CVEs without providing any supporting PoC, exploit, or mitigation details.

    1000078
    42 followersView on X
  • MAKHLOUF Med@CameleonGoods
    Active Exploitation

    تحذير أمني حاسم لمطوري PHP على خوادم ويندوز! تم الكشف عن ثغرة خطيرة (CVE-2024-4577) تسمح بتنفيذ الأوامر عن بعد عند تشغيل PHP في وضع CGI، مما يعرض الخادم لخطر الاختراق الكامل. الفائدة من التحديث الفوري هي حماية بياناتك وتطبيقاتك من هجمات وشيكة، حيث تم رصد استغلال لهذه الثغرة بالفعل. ينصح بشدة بالتحديث الفوري إلى الإصدارات الآمنة (PHP 8.3.8, 8.2.20, و 8.1.29) لتأمين خوادمك. #أمن_المعلومات #سيرفر #ويندوز #PHP

    Post summary

    CVE-2024-4577 is a remote command‑execution flaw in PHP CGI on Windows, being actively exploited; immediate patching to the latest secure PHP releases is urged.

    0100056
    1.1K followersView on X
  • MAKHLOUF Med@CameleonGoods
    Patch

    أصدرت المديرية العامة لأمن نظم المعلومات في المغرب تحذيراً حرجاً بخصوص ثغرة أمنية خطيرة (CVE-2024-4577) تؤثر على إصدارات PHP المثبتة على نظام ويندوز، مما قد يسمح للمهاجمين بتنفيذ تعليمات برمجية عن بعد. تكمن خطورة الثغرة في أنها تسمح بتجاوز آليات حماية سابقة وقد تؤدي إلى اختراق كامل للخوادم المتأثرة. لذلك، يوصي مركز اليقظة والرصد والتصدي للهجمات الحاسوبية (ma-CERT) بضرورة تطبيق التحديثات الأمنية الأخيرة التي أصدرها مطورو PHP بشكل فوري. شارك هذا التحذير الهام. #المغرب #الأمن_السيبراني #PHP #Cybersecurity

    Post summary

    A Moroccan security advisory (ma-CERT) warns that CVE-2024-4577 allows remote code execution on PHP for Windows and urges users to apply the latest PHP security updates immediately, with no evidence of active exploitation or PoC.

    0001077
    1.1K followersView on X
  • sicehice@sicehice
    Active Exploitation

    PHP-CGI RCE attempt observed (CVE-2024-4577) 2026-05-11 02:15:08 UTC Source IP: 130.78.217.194 🇬🇧 POST /cgi-bin/param.cgi?post_raw IOCs: 130.78.217.194 🇬🇧 hxxp://130.78.217.194:8888/bot.sh 06f55a73b369040bee42de084027d3dc https://t.co/UjDd4lcPGH

    Post summary

    An attempt to exploit PHP‑CGI (CVE‑2024‑4577) was observed from a UK IP, with a bot script IP provided, but no PoC, exploit code, patch, or technical details were disclosed.

    0001010.7K
    1.7K followersView on X
  • Aviatrix Threat Research Center@aviatrixtrc
    Active Exploitation

    TRC analysis shows RedTail cryptomining campaign exploiting CVE-2024-4577 PHP vulnerability with 'libredtail-http' User-Agent. Attackers achieve remote code execution, deploy miners, and establish C2 connections for resource hijacking. #ZeroDay #ThreatIntel 🔗 Full TRC analysis: https://aviatrix.ai/threat-research-center/danger-of-libredtail-guest-diary-2026-04-29

    Post summary

    CVE-2024-4577 is being actively exploited by the RedTail cryptomining campaign to gain remote code execution, deploy miners, and establish C2 connections; no PoC, patch, or exploit code is disclosed.

    00010109
    1.9K followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    Vendor v9.8. CVE-2024-4577 is a character encoding vulnerability specific to PHP CGI deployments on Windows systems. CVSS 9.8 (CRITICAL) | PHP 8.1-8.3 (Windows CGI) | Best-Fit Character Conversion Bypass → Unauthenticated RCE

    Post summary

    The text announces a new critical PHP CGI vulnerability (CVE-2024-4577) affecting Windows deployments, providing technical details such as CVSS score and potential for unauthenticated RCE.

    1000035
    125 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CVE-2024-4577. CVSS 9.8 (CRITICAL) | PHP 8.1-8.3 (Windows CGI) | Best-Fit Character Conversion Bypass → Unauthenticated RCE

    Post summary

    The post announces the discovery of CVE‑2024‑4577, detailing its critical severity, affected PHP versions, and the bypass leading to unauthenticated remote code execution.

    1000047
    125 followersView on X
  • Lyrie.ai@lyrie_ai
    Active Exploitation

    03:00 UTC: First exploit attempt in the wild. CVE-2024-4577: PHP-CGI RCE via Windows Best-Fit Character Conversion

    Post summary

    First exploit attempt documented for CVE-2024-4577, indicating active exploitation in the wild.

    1000033
    125 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    00:00 UTC: CVE-2024-4577 disclosed. CVE-2024-4577: PHP-CGI RCE via Windows Best-Fit Character Conversion

    Post summary

    The text announces CVE-2024-4577, a PHP‑CGI remote code execution vulnerability caused by Windows best‑fit character conversion, without mentioning PoC, exploit code, or patches.

    1000040
    125 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    00:11 UTC: GPT-5 enrichment complete. 1,031 words. 3 citations. CVE-2024-4577: PHP-CGI RCE via Windows Best-Fit Character Conversion

    Post summary

    The text announces CVE-2024-4577 as a PHP-CGI remote code execution flaw caused by Windows best‑fit character conversion, without providing exploit details or patch information.

    1000032
    125 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    00:03 UTC: Lyrie Sentinel flagged it. CVE-2024-4577: PHP-CGI RCE via Windows Best-Fit Character Conversion

    Post summary

    CVE-2024-4577 is a PHP-CGI remote code execution vulnerability exploiting Windows best‑fit character conversion, with no PoC, exploit code, or active exploitation disclosed.

    1000028
    125 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    https://research.lyrie.ai/research/cve-2024-4577-php-cgi-windows-character-encoding-rce #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The text references a research link about CVE-2024-4577 but provides no further details or actionable information.

    0000022
    125 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    https://research.lyrie.ai/research/cve-2024-4577-php-cgi-rce-windows-best-fit-character-conversion #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The post simply shares a research article URL about CVE-2024-4577 without providing any direct information on exploitation, patches, or technical details.

    0000020
    125 followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
OSfedoraprojectfedora39--
OSfedoraprojectfedora40--
OSmicrosoftwindows---
Appphpphp---

Explore more