AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .9999 100.0 YES
AFFECTED Product Versions Fixed PHP 8.1.* – —
TIMELINE May 6 Reserved by php Jun 9 Published (CNA: php) Jun 12 Added to CISA KEV, remediation due 2024-07-03
Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
AV AC PR UI S C I A CVSS EPSS %ile KEV N L N N U H H H 9.8 .9999 100.0 YES
AFFECTED Product Versions Fixed PHP 8.1.* – —
TIMELINE May 6 Reserved by php Jun 9 Published (CNA: php) Jun 12 Added to CISA KEV, remediation due 2024-07-03
In PHP versions 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, when using Apache and PHP-CGI on Windows, if the system is set up to use certain code pages, Windows may use "Best-Fit" behavior to replace characters in command line given to Win32 API functions. PHP CGI module may misinterpret those characters as PHP options, which may allow a malicious user to pass options to PHP binary being run, and thus reveal the source code of scripts, run arbitrary PHP code on the server, etc.
| Date | Event | Detail |
|---|---|---|
| May 6, 2024 | Reserved | Reserved by php |
| June 9, 2024 | Published | Published (CNA: php) |
| June 12, 2024 | KEV ADDED | Added to CISA KEV, remediation due 2024-07-03 |
| Vendor | Product / Package | Ecosystem | Version introduced | Fixed |
|---|---|---|---|---|
| PHP Group | PHP | — | 8.1.* | — |
Authoritative record: CVE-2024-4577 at cve.org
Vendors: php group
Weaknesses: CWE-78
This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2024-4577 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Sunday, October 4, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.