CRITICAL 9.8 Microsoft PoC

CVE-2024-4577

Argument Injection in PHP-CGI

Microsoft Security Update 2024-Jun: Argument Injection in PHP-CGI

Affected Products

References

Published: 2024-06-11 · Source: Microsoft · Feed updated: 2026-09-17
This critical severity vulnerability with a CVSS score of 9.8 was published on 2024-06-11 via Microsoft. 🚨 A public proof-of-concept exploit is available on GitHub. EPSS score: 100.0% (top 0% of all CVEs by exploitation probability). Affected: cbl2 php 8.1.29-1 on CBL Mariner 2.0, azl3 php 8.3.8-1 on Azure Linux 3.0, cbl2 php 8.1.28-1 on CBL Mariner 2.0 and 1 more.

Risk Timeline

CVE Disclosed2024-06-11 · 827 days ago
Public PoC Exploit AvailableWeaponised proof-of-concept code is publicly accessible

Remediation Resources

Related Vulnerabilities

CVETitleSeverityCVSS
CVE-2025-49844 PoCRedis Lua Use-After-Free may lead to remote code executionCRITICAL9.9
CVE-2024-41110 PoCMoby authz zero length regressionCRITICAL9.9
CVE-2024-24790Unexpected behavior from Is methods for IPv4-mapped IPv6 addresses in net/netipCRITICAL9.8
CVE-2024-39331In Emacs before 29.4 org-link-expand-abbrev in lisp/ol.el expands a %(...) link CRITICAL9.8
CVE-2024-38541of: module: add buffer overflow check in of_modalias()CRITICAL9.8
CVE-2020-19692Buffer Overflow vulnerabilty found in Nginx NJS v.0feca92 allows a remote attackCRITICAL9.8
vulnfeed aggregates 8294 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.