HomeUpdatesPHP: Fix for vulnerability affecting all Windows versions

PHP: Fix vulnerability affecting all Windows versions

A new vulnerability in PHP for Windows allows remote code execution (RCE) and affects all versions since version 5.x. This means that many users are at risk.

PHP Windows vulnerability

PHP is a widely used open-source scripting language, suitable for web development. It is used on both Windows and Linux servers.

The vulnerability is tracked as CVE-2024-4577 and was discovered by Devcore researcher Orange Tsai on May 7, 2024 (who reported it to PHP developers).

See also: Muhstik botnet exploits vulnerability in Apache RocketMQ

The PHP project maintainers released a patch yesterday, addressing the vulnerability.

However, implementing security updates to a project with such widespread use and development is complicated and could leave a significant number of systems vulnerable to attacks.

When a critical vulnerability affecting multiple devices is revealed, malicious hackers and researchers immediately begin searching for vulnerable systems.

For example, the Shadowserver Foundation has already identified multiple IP addresses that scan for servers vulnerable to the CVE-2024-4577 vulnerability.

CVE-2024-4577

As previously reported, the CVE-2024-4577 vulnerability in the PHP language allows malicious hackers to perform remote code execution. More details on how the vulnerability works and how it is caused can be found in the DevCore report

See also: Critical vulnerabilities in WooCommerce Amazon Affiliates plugin

PHP: Fix vulnerability affecting all Windows versions

As Devcore says, the CVE-2024-4577 vulnerability affects all versions of PHP for Windows. Those using PHP 8.0 (End of Life), PHP 7.x (End of Life), or PHP 5.x (End of Life) will also need to upgrade to a newer version or use the following measures.

Restoration

Those using supported PHP versions should upgrade to the versions that incorporate the patches: PHP 8.3.8, PHP 8.2.20, and PHP 8.1.29.

For systems that cannot be upgraded immediately and users of EoL versions, it is recommended to implement a mod_rewrite rule, such as the following:

RewriteEngine On

RewriteCond %{QUERY_STRING} ^%ad [NC]

RewriteRule .? – [F,L]

This new vulnerability highlights the importance of regularly updating and patching software to breaches security. With PHP being so widely used, it is important for system administrators and developers to keep their systems up to date with the latest security patches.

See also: Cisco: Fixed Webex vulnerabilities used for German government surveillance

Additionally, this new RCE vulnerability in PHP serves as a reminder of the ever-evolving threat landscape and the importance of remaining vigilant when it comes to cybersecurity. It is important for organizations to have dedicated teams and resources to regularly monitor and respond to potential security.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS