CVE-2024-4577 — exploited in the wild
CVE-2024-4577: CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in PHP Group PHP
Observed by OffSeq honeypot sensors · last 7 days · last seen 2026-08-31
About CVE-2024-4577
In PHP versions 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, when using Apache and PHP-CGI on Windows, if the system is set up to use certain code pages, Windows may use "Best-Fit" behavior to replace characters in command line given to Win32 API functions. PHP CGI module may misinterpret those characters as PHP options, which may allow a malicious user to pass options to PHP binary being run, and thus reveal the source code of scripts, run arbitrary PHP code on the server, etc.
Vendor: PHP GroupCWE-78
OffSeq's global honeypot fleet recorded 471 exploitation attempts against CVE-2024-4577 from 63 distinct attacker networks in the last 7 days. This is direct in-the-wild telemetry — every hit is a real attacker probing a decoy, not a scan of a vulnerability database.
Top attacking countries
- Germany166
- United States88
- Canada83
- United Kingdom58
- The Netherlands53
- Singapore16
Top attacking networks
Techniques observed
Sample request paths
/php-cgi/php-cgi.exe