boxscore/security
CVE · referencelatest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CVE-2024-4577

PHP Group PHP — Argument Injection in PHP-CGI
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS    %ile   KEV
   N   L   N   N  U  H  H  H    9.8   .9999   100.0   YES
AFFECTED
  Product  Versions  Fixed
  PHP      8.1.* –   —
TIMELINE
  May 6   Reserved by php
  Jun 9   Published (CNA: php)
  Jun 12  Added to CISA KEV, remediation due 2024-07-03
CWE-78 · CNA: php · CVSS v3.1 · 23 references · KEV due July 3, 2024

Description

In PHP versions 8.1.* before 8.1.29, 8.2.* before 8.2.20, 8.3.* before 8.3.8, when using Apache and PHP-CGI on Windows, if the system is set up to use certain code pages, Windows may use "Best-Fit" behavior to replace characters in command line given to Win32 API functions. PHP CGI module may misinterpret those characters as PHP options, which may allow a malicious user to pass options to PHP binary being run, and thus reveal the source code of scripts, run arbitrary PHP code on the server, etc.

Lifecycle

Complete event history — 3 events, chronological
DateEventDetail
May 6, 2024ReservedReserved by php
June 9, 2024PublishedPublished (CNA: php)
June 12, 2024KEV ADDEDAdded to CISA KEV, remediation due 2024-07-03

Affected

Affected products and packages — 1 row
VendorProduct / PackageEcosystemVersion introducedFixed
PHP GroupPHP—8.1.*—

Weaknesses

CWE-78

References (23)

Related

Authoritative record: CVE-2024-4577 at cve.org

Vendors: php group

Weaknesses: CWE-78

About this page

This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2024-4577 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Sunday, October 4, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.