FortiGuard Outbreak Alert: PHP RCE Attack
| Description | CVE-2024-4577 is an argument injection vulnerability affecting PHP when using Apache and PHP-CGI on Windows systems. This vulnerability stems from improper character encoding conversions to achieve remote code execution (RCE). The affected PHP versions are:
TellYouThePass ransomware gang has been leveraging CVE-2024-4577, a remote code execution vulnerability in PHP to deliver web shells and deploy ransomware on targeted systems. | ||||||
| CVE ID | CVE-2024-4577 (https://nvd.nist.gov/vuln/detail/CVE-2024-4577) | ||||||
| NDR Cloud Detection Rule | FortiNDR Cloud v2024.5+
| ||||||
| Playbook | N/A | ||||||
| Threat Hunting | FortiNDR Cloud users can use the following IOCs from Fortinet to hunt for “PHP RCE Attack” related activities All IOCs listed above have been added to Threat Intelligence Intel | ||||||
| Suricata Coverage | N/A | ||||||
| Other Fortinet Products | For more details regarding mitigating the vulnerability by utilizing Fortinet products, please refer to |
