Argument Injection in PHP-CGI
Published Jun 9, 2024 ·Due Jul 3, 2024
9.8
CRITICALCVSS 3.1
EPSS 99.99%
Description
In PHP versions 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, when using Apache and PHP-CGI on Windows, if the system is set up to use certain code pages, Windows may use "Best-Fit" behavior to replace characters in command line given to Win32 API functions. PHP CGI module may misinterpret those characters as PHP options, which may allow a malicious user to pass options to PHP binary being run, and thus reveal the source code of scripts, run arbitrary PHP code on the server, etc.
Affected products
-
Affected
- ≥ 8.1.*, < 8.1.29
- ≥ 8.2.*, < 8.2.20
- ≥ 8.3.*, < 8.3.8
-
Affected
- ≥ 8.1.0, < 8.1.29
- ≥ 8.2.0, < 8.2.20
- ≥ 8.3.0, < 8.3.8
Red Hat Enterprise Linux 10
php
Not affected
Red Hat Enterprise Linux 6
php
Not affected
Red Hat Enterprise Linux 7
php
Not affected
Red Hat Enterprise Linux 8
php:7.4/php
Not affected
Red Hat Enterprise Linux 8
php:8.0/php
Not affected
Red Hat Enterprise Linux 8
php:8.2/php
Not affected
Red Hat Enterprise Linux 9
php
Not affected
Red Hat Enterprise Linux 9
php:8.1/php
Not affected
Red Hat Enterprise Linux 9
php:8.2/php
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 10 | php | Not affected | n/a |
| Red Hat Enterprise Linux 6 | php | Not affected | n/a |
| Red Hat Enterprise Linux 7 | php | Not affected | n/a |
| Red Hat Enterprise Linux 8 | php:7.4/php | Not affected | n/a |
| Red Hat Enterprise Linux 8 | php:8.0/php | Not affected | n/a |
| Red Hat Enterprise Linux 8 | php:8.2/php | Not affected | n/a |
| Red Hat Enterprise Linux 9 | php | Not affected | n/a |
| Red Hat Enterprise Linux 9 | php:8.1/php | Not affected | n/a |
| Red Hat Enterprise Linux 9 | php:8.2/php | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
No Red Hat products are affected by this CVE.
Red Hat mitigation
Mitigation for this issue is either not available or the currently available options don't meet the Red Hat Product Security criteria comprising ease of use and deployment, applicability to widespread installation base or stability.
References (29)
- http://www.openwall.com/lists/oss-security/2024/06/07/1 Mailing ListThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2024-4577 Vendor Advisory
- https://arstechnica.com/security/2024/06/php-vulnerability-allows-attackers-to-run-malicious-code-on-windows-servers/ ExploitPress/Media CoverageThird Party Advisory
- https://blog.orange.tw/2024/06/cve-2024-4577-yet-another-php-rce.html Third Party Advisory
- https://blog.talosintelligence.com/new-persistent-attacks-japan/ ExploitThird Party Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=2291281 Issue Tracking
- https://cert.be/en/advisory/warning-php-remote-code-execution-patch-immediately Third Party Advisory
- https://devco.re/blog/2024/06/06/security-alert-cve-2024-4577-php-cgi-argument-injection-vulnerability-en/ ExploitThird Party Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-44188 Advisory
- https://github.com/11whoami99/CVE-2024-4577 Exploit
- https://github.com/php/php-src/security/advisories/GHSA-3qgc-jrrr-25jv ExploitThird Party Advisory
- https://github.com/rapid7/metasploit-framework/pull/19247 ExploitIssue TrackingPatch
- https://github.com/watchtowrlabs/CVE-2024-4577 ExploitThird Party Advisory
- https://github.com/xcanwin/CVE-2024-4577-PHP-RCE ExploitThird Party Advisory
- https://isc.sans.edu/diary/30994 ExploitThird Party Advisory
- https://labs.watchtowr.com/no-way-php-strikes-again-cve-2024-4577/ ExploitThird Party Advisory
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PKGTQUOA2NTZ3RXN22CSAUJPIRUYRB4B/ Mailing List
- https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/W45DBOH56NQDRTOM2DN2LNA2FZIMC3PK/ Mailing List
- https://nvd.nist.gov/vuln/detail/CVE-2024-4577
- https://security.netapp.com/advisory/ntap-20240621-0008/ Third Party Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-4577 government-resourceUS Government Resource
- https://www.cve.org/CVERecord?id=CVE-2024-4577
- https://www.imperva.com/blog/imperva-protects-against-critical-php-vulnerability-cve-2024-4577/ Third Party Advisory
- https://www.php.net/ChangeLog-8.php#8.1.29 Release Notes
- https://www.php.net/ChangeLog-8.php#8.2.20 Release Notes
- https://www.php.net/ChangeLog-8.php#8.3.8 Release Notes
- https://www.vicarius.io/vsociety/posts/php-cgi-argument-injection-to-rce-cve-2024-4577 ExploitThird Party Advisory
- https://www.vicarius.io/vsociety/posts/php-cgi-os-command-injection-vulnerability-cve-2024-4577 ExploitThird Party Advisory
Change history (0)
No recorded changes yet.
CVE.org / MITRE
CISA Vulnrichment
ENISA EUVD
GitHub
No data