Mass Exploitation of PHP Vulnerability CVE-2024-4577: A Growing Global Threat

Listen to this Post

A critical security flaw in PHP, tracked as CVE-2024-4577, has raised alarms among cybersecurity professionals as it is actively exploited by attackers worldwide. This vulnerability, which affects PHP installations running in CGI mode on Windows systems, was patched in June 2024 but has now been identified as a key target for malicious actors. Cyber threat intelligence firm GreyNoise has issued a warning, indicating that exploitation attempts have surged since January 2025, with significant attempts coming from various regions, including Japan, the United States, Germany, and China.

The vulnerability allows unauthenticated attackers to execute arbitrary code on vulnerable systems, potentially leading to complete system compromise. While the flaw was addressed with patches released in June 2024, the discovery of proof-of-concept (PoC) exploit code and growing exploitation attempts highlight a concerning trend. Cybercriminals are not only targeting specific regions but have widened their scope to global targets, with substantial increases in attacks observed in the first quarter of 2025. This article explores the evolution of the CVE-2024-4577 exploit, its global impact, and insights into how organizations can defend against such threats.

the CVE-2024-4577 Vulnerability and Exploitation Patterns

CVE-2024-4577 is a PHP-CGI argument injection vulnerability affecting PHP installations running in CGI mode on Windows systems. The flaw was initially patched in June 2024, following the release of a patch by PHP maintainers on June 7, 2024. However, despite the patch, the vulnerability has become a focal point for cybercriminals, as evidenced by the release of proof-of-concept (PoC) exploit code by WatchTowr Labs just a day after the patch was made available. This was followed by reports from the Shadowserver Foundation, which observed the first exploitation attempts.

Cisco Talos also reported that, since at least early January 2025, attackers have targeted Japanese organizations using this vulnerability. While their primary goal appeared to be credential harvesting, further analysis of the post-exploitation activities indicated that attackers were trying to establish persistence, escalate privileges, and deploy tools like Cobalt Strike, suggesting more malicious intentions beyond credential theft.

GreyNoise’s data further expanded on this, revealing that exploitation of CVE-2024-4577 has spread well beyond Japan. In January 2025 alone, their Global Observation Grid (GOG) identified 1,089 unique IP addresses attempting to exploit the vulnerability worldwide. Countries including the United States, Singapore, Japan, Germany, and China saw significant increases in attempted exploits.

Of particular concern is the increasing sophistication of these attacks. In February 2025, a coordinated spike in exploit attempts indicated that attackers were using automated scanning methods to identify vulnerable systems. Additionally, the vulnerability has been exploited by groups such as the TellYouThePass ransomware gang, which began deploying webshells and encrypting victim systems shortly after the vulnerability was discovered.

One of the more notable incidents involved unknown attackers backdooring a Taiwanese university’s Windows systems with newly discovered malware named Msupedge. These attacks highlight the diverse range of malicious activities being carried out through this vulnerability.

What GreyNoise Says:

The information presented by GreyNoise paints a concerning picture of the ongoing exploitation of CVE-2024-4577. According to their data, attacks targeting this vulnerability have escalated since January 2025, with an alarming rise in exploitation attempts across multiple countries. GreyNoise’s Global Observation Grid (GOG), a network of honeypots designed to detect malicious activity, reported over 1,000 unique IP addresses attempting to exploit the flaw in January alone. The widespread nature of the attacks—spanning across countries such as the United States, Japan, Singapore, and Germany—indicates that cybercriminals are actively scanning the internet for vulnerable systems.

What makes this vulnerability particularly dangerous is its potential for enabling attackers to compromise entire systems. The flaw allows unauthenticated users to execute arbitrary code on vulnerable systems, essentially granting them full control. This level of access can lead to the deployment of malware, data exfiltration, and the establishment of persistent backdoors.

GreyNoise also highlights the role of exploit availability in the ongoing exploitation of CVE-2024-4577. With at least 79 exploit variants available online, attackers have a wide array of tools to leverage the vulnerability, increasing the likelihood of continued and widespread exploitation. Additionally, the observation of coordinated spikes in attacks suggests that attackers are using automated systems to identify and exploit vulnerable systems on a large scale.

The use of advanced tools such as the “TaoWu” Cobalt Strike kit plugins further underscores the sophistication of the attackers behind these campaigns. These tools are typically associated with highly organized and skilled cybercriminal groups, indicating that the exploitation of CVE-2024-4577 is not just opportunistic but part of a well-coordinated and planned attack.

GreyNoise’s findings also emphasize the global scope of these attacks. While initial reports focused on exploitation attempts in Japan, their data clearly shows that the exploitation of CVE-2024-4577 is not isolated to a single region. Countries across the globe are experiencing increased attempts to exploit this vulnerability, indicating that attackers are casting a wide net in search of vulnerable systems.

This trend of widening attack vectors and increasing exploitation attempts highlights the importance of rapid patching and robust defense mechanisms. Organizations need to ensure that they have up-to-date security patches and are actively monitoring for suspicious activity on their networks to mitigate the risks posed by this vulnerability.

Fact Checker Results

  • GreyNoise’s data confirms a significant rise in exploitation attempts, with over 1,000 unique IP addresses targeting CVE-2024-4577 in January 2025.

– The

  • The exploitation of CVE-2024-4577 has been linked to sophisticated post-exploitation activities, including the deployment of advanced adversarial tools like Cobalt Strike.

References:

Reported By: https://www.bleepingcomputer.com/news/security/critical-php-rce-vulnerability-mass-exploited-in-new-attacks/
Extra Source Hub:
https://www.reddit.com
Wikipedia
Undercode AI

Image Source:

Pexels
Undercode AI DI v2

Join Our Cyber World:

💬 Whatsapp
💬 TelegramFeatured Image