Skip to main content Skip to local navigation

PHP CGI Vulnerability (CVE-2024-4577)

 

A picture containing text  Description automatically generated

 

Service Advisory 

 

A critical PHP vulnerability (CVE-2024-4577), discovered last year is currently being exploited in the wild. A successful exploitation of this vulnerability could allow an unauthenticated attacker to execute arbitrary code on the vulnerable PHP server, leading to complete system compromise and deliver malware including ransomware.

Severity level: 
CVSS Score: 9.8/Critical

Description
:
PHP is a widely used open-source scripting language commonly used for web development and commonly used on both Windows and Linux servers. PHP CGI is a method of running PHP scripts through the Common Gateway Interface (CGI) to handle HTTP requests and generate dynamic web content. This vulnerability affects PHP installations on the Windows operating system, which either run PHP under CGI mode or expose the PHP binary.

Affected Versions
:

PHP 8.3 versions earlier than 8.3.8

PHP 8.2 versions earlier than 8.2.20

PHP 8.1 versions earlier than 8.1.29

Impact:
This Vulnerability if exploited could lead to the execution of arbitrary code, a scenario with severe consequences for system integrity and data security.

Resolution:
Upgrade to the latest version.

Reference:

https://www.cvedetails.com/cve/CVE-2024-4577/

www.cyber.gc.ca/en/alerts-advisories/al25-001-mass-exploitation-critical-php-cgi-vulnerability-cve-2024-4577https://www.bleepingcomputer.com/news/security/critical-php-rce-vulnerability-mass-exploited-in-new-attacks/

https://www.php.net/downloads.php

https://www.securityweek.com/mass-exploitation-of-critical-php-vulnerability-begins/

https://www.bitsight.com/blog/cve-2024-4577-windows-encoding-gone-wrong

UIT Information Security

Contact

IT Client Services at askIT@yorku.ca or 416 736 5800

 

PRIVACY POLICY | VISIT WWW.YORKU.CA
This email was sent by: York University, 4700 Keele Street, Toronto, Ontario M3J 1P3

This email is viewed best in Microsoft Outlook for web