Skip to main content

New versions of PHP address a critical vulnerability that could lead to arbitrary PHP code execution

Summary

New versions of PHP address a critical vulnerability that could lead to arbitrary PHP code execution

Affected platforms

The following platforms are known to be affected:

Threat details

Introduction

DEVCORE has discovered a critical security vulnerability in PHP versions installed on Microsoft Windows operating system (OS).  PHP is a widely used open-source general-purpose scripting language that is especially suited for web development and can be embedded into HTML.

The CGI argument injection vulnerability is known as CVE-2024-4577 and has a CVSSv3.1 score of 9.8. An attacker could exploit this vulnerability to execute arbitrary PHP code on vulnerable instances.

Remediation advice

Affected organisations are encouraged to review the DEVCORE security alert and follow the remediation guidance as soon as possible.

Definitive source of threat updates

CVE Vulnerabilities

Last edited: 11 June 2024 12:48 pm