Temporary Advertisements:
Ad
Ad
Ad
Critical PHP RCE vulnerability mass exploited in new attacks
by lulagain - Tuesday March 11, 2025 at 10:13 PM
#1
Threat intelligence company GreyNoise warns that a critical PHP remote code execution vulnerability that impacts Windows systems is now under mass exploitation.
Tracked as CVE-2024-4577, this PHP-CGI argument injection flaw was patched in June 2024 and affects Windows PHP installations with PHP running in CGI mode. Successful exploitation enables unauthenticated attackers to execute arbitrary code and leads to complete system compromise following successful exploitation.
A day after PHP maintainers released CVE-2024-4577 patches on June 7, 2024, WatchTowr Labs released proof-of-concept (PoC) exploit code, and the Shadowserver Foundation reported observing exploitation attempts.
GreyNoise's warning comes after Cisco Talos revealed earlier that an unknown attacker had exploited the same PHP vulnerability to target Japanese organizations since at least early January 2025.
While Talos observed the attackers attempting to steal credentials, it believes their goals extend beyond just credential harvesting, based on post-exploitation activities, which include establishing persistence, elevating privileges to SYSTEM level, deployment of adversarial tools and frameworks, and usage of "TaoWu" Cobalt Strike kit plugins.
New attacks expand to targets worldwide
However, as GreyNoise reported, the threat actors behind this malicious activity cast a much wider net by targeting vulnerable devices globally, with significant increases observed in the United States, Singapore, Japan, and other countries since January 2025.
In January alone, its worldwide network of honeypots known as Global Observation Grid (GOG) spotted 1,089 unique IP addresses attempting to exploit this PHP security flaw.
"While initial reports focused on attacks in Japan, GreyNoise data confirms that exploitation is far more widespread [..] More than 43% of IPs targeting CVE-2024-4577 in the past 30 days are from Germany and China," the threat intelligence firm said, warning that at least 79 exploits are available online.
"In February, GreyNoise detected a coordinated spike in exploitation attempts against networks in multiple countries, suggesting additional automated scanning for vulnerable targets."
Previously, CVE-2024-4577 was exploited by unknown attackers who backdoored a university's Windows systems in Taiwan with newly discovered malware dubbed Msupedge.
The TellYouThePass ransomware gang also started exploiting the vulnerability to deploy webshells and encrypt victims' systems less than 48 hours after patches were released in June 2024.
[Image: 128.gif]
@AterĀ  @antisocial My Nigga's
Reply


Possibly Related Threads…
Thread Author Replies Views Last Post
  Corruptiion of PLN [Indonesia] - 2025 Investigation Viral LordZeroDay 35 5,658 6 hours ago
Last Post: agus123
  Breached forums and clones? fda5b 8 3,208 11 hours ago
Last Post: binaryplay
  epsilon hacker "Chat Noir" arrested for FREE SAS breach Angel_Batista 24 4,536 Sep 18, 2026, 04:17 PM
Last Post: krassimiryo
  Claude Mythos biyukean 7 1,116 Sep 05, 2026, 03:33 PM
Last Post: fkcca
  BreachForums Leak Free Data KingJulien 187 20,163 Sep 02, 2026, 09:50 PM
Last Post: kh3rnz

Forum Jump:


 Users browsing this forum: