MIRAGE
Threat IntelligenceCVEs › CVE-2024-4577

CVE-2024-4577 — exploited in the wild

Argument Injection in PHP-CGI (CVE-2024-4577)

Exploitation observed by OffSeq honeypot sensors · last 30 days · last seen 4 hours ago · first observed 2026-08-19 (28 days ago)

1,817
Exploitation attempts
78
Distinct source IPs
1
Exposed hosts
9.8
CVSS
100.0%
EPSS
KEV
CISA Known-Exploited

Listed in CISA's Known Exploited Vulnerabilities catalog and still under active attack against OffSeq honeypot decoys.

About CVE-2024-4577

A critical vulnerability (CVE-2024-4577) affects PHP-CGI on Windows when used with Apache and certain code pages. In PHP versions 8.1.* before 8.1.29, 8.2.* before 8.2.20, and 8.3.* before 8.3.8, Windows may apply "Best-Fit" character replacement in command-line arguments, causing PHP-CGI to misinterpret these as PHP options. This can allow attackers to pass malicious options to the PHP binary, potentially exposing source code or enabling arbitrary code execution.

OffSeq's global honeypot fleet recorded 1,817 exploitation attempts against CVE-2024-4577 from 78 distinct source IPs in the last 30 days — direct in-the-wild telemetry: every hit is a real attacker probing a decoy, not a scan of a vulnerability database. It is also present on 1 internet-exposed hosts OffSeq tracked in the last 30 days.

Open the live CVE-2024-4577 view →

References