MIRAGE
Threat IntelligenceCVEs › CVE-2024-4577

CVE-2024-4577 — exploited in the wild

CVE-2024-4577: CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in PHP Group PHP

Observed by OffSeq honeypot sensors · last 7 days · last seen 2026-08-31

471
Exploitation attempts
63
Attacker networks
438
Sessions
9.8
CVSS
KEV
CISA Known-Exploited

About CVE-2024-4577

In PHP versions 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, when using Apache and PHP-CGI on Windows, if the system is set up to use certain code pages, Windows may use "Best-Fit" behavior to replace characters in command line given to Win32 API functions. PHP CGI module may misinterpret those characters as PHP options, which may allow a malicious user to pass options to PHP binary being run, and thus reveal the source code of scripts, run arbitrary PHP code on the server, etc.

Vendor: PHP GroupCWE-78

OffSeq's global honeypot fleet recorded 471 exploitation attempts against CVE-2024-4577 from 63 distinct attacker networks in the last 7 days. This is direct in-the-wild telemetry — every hit is a real attacker probing a decoy, not a scan of a vulnerability database.

Top attacking countries

Top attacking networks

Techniques observed

Sample request paths

/php-cgi/php-cgi.exe

Open the live CVE-2024-4577 view →

References