EXPOSURES › CVE-2024-4577
CVE-2024-4577
CRITICAL ⌖ ON CISA KEV · EXPLOITEDA patch bypass for a 2012 PHP-CGI command injection flaw allows remote code execution on Windows systems, proving years of negligence.
This vulnerability is a patch bypass for CVE-2012-1823, meaning the flaw has been known and unpatched for over a decade. It allows arbitrary code execution on Windows-based PHP CGI environments, directly enabling ransomware attacks. DIB organizations must audit their PHP CGI deployments and apply patches immediately, as relying on a vendor to fix a known issue years later is a severe compliance failure.
Shame score — The vendor failed to patch a known vulnerability for over 12 years, allowing it to be exploited in the wild and linked to ransomware, demonstrating extreme negligence.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
PHP, specifically Windows-based PHP used in CGI mode, contains an OS command injection vulnerability that allows for arbitrary code execution. This vulnerability is a patch bypass for CVE-2012-1823.