PHP Vulnerability Found: Researchers Warn of Remote Code Execution Risk

11 Jun 2024

Cybersecurity Researchers Uncover New PHP Vulnerability

Cybersecurity researchers have recently identified a new vulnerability in PHP that could potentially allow hackers to execute malicious code remotely. Known as CVE-2024-4577, this vulnerability is classified as a CGI argument injection vulnerability.

As of now, the severity of this vulnerability has not been determined. However, it has been confirmed that it impacts all versions of PHP running on the Windows operating system. Interestingly, this vulnerability was inadvertently introduced while attempting to address a separate flaw.

The Hacker News and the Shadowserver Foundation have reported instances of hackers actively scanning endpoints for this vulnerability. The Shadowserver Foundation issued a warning stating, “Attention! We see multiple IPs testing PHP/PHP-CGI CVE-2024-4577 against our honeypot sensors starting today, June 7th. Vulnerability affects PHP running on Windows.”

DEVCORE has also highlighted that XAMPP installations on Windows are particularly vulnerable when configured to use Traditional Chinese, Simplified Chinese, or Japanese locales. To mitigate the risk, administrators are advised to replace outdated PHP CGI with more secure alternatives like Mod-PHP, FastCGI, or PHP-FPM.

Describing the vulnerability as deceptively simple yet intriguing, the researchers remarked, “Who would have imagined that a patch considered secure for over a decade could be circumvented due to a minor Windows feature?”

Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!

More from TechRadar Pro

Top charts for Desktop Windows

uTorrent

uTorrent

Latest update uTorrent download for free for Windows PC or Android mobile

5
1032 reviews
6833499
downloads
Zona

Zona

Latest update Zona download for free for Windows PC or Android mobile

4
614 reviews
1470578
downloads
WinRAR

WinRAR

Latest update WinRAR download for free for Windows PC or Android mobile

5
735 reviews
609176
downloads
Minecraft

Minecraft

Latest update Minecraft download for free for Windows PC or Android mobile

5
750 reviews
468704
downloads

News and reviews for Desktop Windows

Neath: New Tactical RPG Announced by Cellar Door Games

Cellar Door Games unveils Neath: a tactical RPG with unique timeline mechanics set for PC release in 2026.

Read more

UN:Me Announced by Shueisha Games for PC

Shueisha Games and historia unveil UN:Me, a psychological horror PC game, for release. Soul-driven mechanics alter player experience.

Read more

Eldamar Studio Launches Lucid Falls for PC on Steam

Eldamar Studio reveals Lucid Falls, a survival horror game on Steam. Players manipulate gravity in a nightmare world.

Read more

Finji Launches CorgiSpace for PC and Mac at $4.99

Finji releases CorgiSpace: an 8-bit arcade collection for PC and Mac, priced at $4.99, available now.

Read more

Launch R-Type Dimensions III for PC in May 2026

ININ Games unveils R-Type Dimensions III for PC in May 2026. Enhanced 3D graphics and new modes redefine the classic R-Type gameplay experience.

Read more

Fanatical's Bundle Offers $1 Chance at SteamDeck OLED

Fanatical's Mystery Bundle gives gamers a chance to win a SteamDeck OLED for $1, offering Steam keys and potential grand prizes.

Read more

FSR Redstone Update Enhances Graphics on RDNA 4 GPUs

AMD's FSR Redstone launches with new graphics features exclusive to RDNA 4 GPUs, improving game visuals and performance.

Read more

AMD Unveils FSR Redstone, Enhancing Radeon Performance

FSR Redstone launches, doubling game support and boosting Radeon RX 9000 cards' capabilities.

Read more

The Temple of Elemental Evil Returns Revamped on Steam

Sneg releases a revamped version of The Temple of Elemental Evil on Steam, featuring over 1,000 improvements for a better gameplay experience.

Read more

Netflix Acquires Warner for $83B, Gaming Studios Undervalued

Netflix bought Warner for $83B, not focusing on gaming studios. Co-CEO Gregory Peters dismisses their valuation in the acquisition.

Read more