A critical remote code execution vulnerability in PHP on Windows, tracked as CVE-2024-4577, allows argument injection in PHP-CGI through Windows Best-Fit character encoding conversion. The flaw affects supported and unsupported PHP 5.x+ versions and is especially dangerous in CGI deployments where php-cgi.exe or php.exe is exposed to the web, including common default XAMPP-style configurations. Researchers reported that specially crafted HTTP requests can bypass prior protections and achieve remote code execution without authentication.
Security updates were released in PHP 8.3.8, 8.2.20, and 8.1.29, but exploitation began rapidly after disclosure. Multiple reports said attackers were using crafted POST requests to launch mshta.exe, retrieve a malicious HTA payload, and execute TellYouThePass ransomware via in-memory VBScript loading. Defenders were urged to patch immediately and, where patching was not yet possible, restrict or disable PHP-CGI exposure and apply web-server filtering and configuration mitigations to block exploit requests.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
4 events from the most recent confirmed update back to the earliest known activity.
watchTowr Labs published a detailed analysis of CVE-2024-4577, further documenting the vulnerability and exploitation mechanics of the PHP issue.
PHP developers released fixes for CVE-2024-4577 in supported branches, with CSIRT.SK identifying patched versions as 8.3.8, 8.2.20, and 8.1.29. The updates addressed a critical Windows PHP-CGI remote code execution issue affecting supported and unsupported 5.x+ versions.
Multiple sources reported active in-the-wild exploitation of CVE-2024-4577 to deliver TellYouThePass ransomware. CSIRT.SK described crafted HTTP POST requests triggering mshta.exe to run a malicious HTA file that decodes and loads malware into memory.
DEVCORE published a security alert describing CVE-2024-4577, a PHP-CGI argument injection vulnerability on Windows caused by Best-Fit character encoding conversion that can lead to remote code execution.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
csirt.sk
Open sourceimperva.com
Open sourcelabs.watchtowr.com
Open sourcedevco.re
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.