Skip to content
COOEY

EXPOSURES › CVE-2024-4577

CVE-2024-4577

CRITICAL ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2024-06-12 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2024-4577 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 95/100 ransomwarerceexploited-in-wildunpatchednegligence

A patch bypass for a 2012 PHP-CGI command injection flaw allows remote code execution on Windows systems, proving years of negligence.

This vulnerability is a patch bypass for CVE-2012-1823, meaning the flaw has been known and unpatched for over a decade. It allows arbitrary code execution on Windows-based PHP CGI environments, directly enabling ransomware attacks. DIB organizations must audit their PHP CGI deployments and apply patches immediately, as relying on a vendor to fix a known issue years later is a severe compliance failure.

Shame score — The vendor failed to patch a known vulnerability for over 12 years, allowing it to be exploited in the wild and linked to ransomware, demonstrating extreme negligence.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

PLAYERS IMPLICATED
DESCRIPTION

PHP, specifically Windows-based PHP used in CGI mode, contains an OS command injection vulnerability that allows for arbitrary code execution. This vulnerability is a patch bypass for CVE-2012-1823.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.