Latest PHP Vulnerability Allows Hackers to Execute Remote Code on Windows Servers

Published:

spot_img

Critical PHP Vulnerability Allows Remote Code Execution on Windows Systems

A critical security flaw has been discovered in PHP that could lead to remote code execution, putting millions of websites at risk. The vulnerability, known as CVE-2024-4577, affects all versions of PHP installed on Windows operating systems.

DEVCORE security researcher Orange Tsai revealed that the flaw allows attackers to bypass previous security measures and execute arbitrary code on remote PHP servers. Despite responsible disclosure on May 7, 2024, exploitation attempts have already been detected within 24 hours of the public disclosure.

In response to the threat, PHP has released patches in versions 8.3.8, 8.2.20, and 8.1.29. However, DEVCORE warns that all XAMPP installations on Windows are vulnerable by default, especially if configured to use Traditional Chinese, Simplified Chinese, or Japanese locales.

To mitigate the risk, DEVCORE recommends moving away from PHP CGI and opting for more secure solutions like Mod-PHP, FastCGI, or PHP-FPM. Security researcher Aliz Hammond emphasized the urgency of applying the patches, as the exploit is relatively simple and has a high likelihood of being used on a large scale.

With the potential for widespread exploitation, website administrators are advised to take immediate action to protect their servers and data. Stay informed and follow us on Twitter and LinkedIn for more exclusive cybersecurity updates.

spot_img

Related articles

Recent articles

India Directs 13 News Outlets to Withdraw Adani Group Coverage

Indian Government Directs Take Down of Adani-Critical Content Overview of the Directive In a significant move, India's Ministry of Information and Broadcasting has instructed 13 digital...

APT28 Unveils Modular Infection Chain Using Steganography and Cloud C2

A Comprehensive Look at APT28’s Phantom Net Voxel Campaign APT28, also known by its multiple aliases such as Fancy Bear, Sofacy, and Sednit, has launched...

ROSHN Group Unveils Sales for Fifth Phase of SEDRA Community

ROSHN Group Launches Fifth Phase of SEDRA Community in Riyadh Introduction to SEDRA's New Phase RIYADH: ROSHN Group, recognized as one of Saudi Arabia’s foremost multi-asset...

Bridgestone Americas Restores Network Connectivity After Cyber Attack

Bridgestone Americas Restores Network Connectivity After Cyber Attack Overview of the Incident Bridgestone Americas, the U.S. branch of the well-known Japanese tire manufacturer, has successfully reinstated...