top of page

New PHP Vulnerability Exposes Windows Servers to Remote Code Execution

Jun 17, 2024

1 min read

A critical PHP vulnerability (CVE-2024-4577) impacting Windows servers allows remote code execution. Discovered by DEVCORE, this CGI argument injection flaw bypasses previous security measures, affecting all PHP versions on Windows. XAMPP installations using certain locales are especially at risk. A patch is available in PHP versions 8.3.8, 8.2.20, and 8.1.29. Immediate updates are recommended due to detected exploitation attempts. Administrators are advised to transition from PHP CGI to more secure alternatives like Mod-PHP or PHP-FPM.


More Information:


https://thehackernews.com/2024/06/new-php-vulnerability-exposes-windows.html

Jun 17, 2024

1 min read

© 2025 by BlueHat Cyber Ltd. All rights reserved.

​

| Privacy Policy |
| Vulnerability Disclosure Policy |

​

BlueHat Cyber Ltd. is a limited company registered in England and Wales. Registered number: 15306261. 
Registered office: 960 Capability Green, Luton, United Kingdom, LU1 3PE

  • X
  • Threads
bottom of page