Ransomware criminals have quickly weaponized an easy-to-exploit vulnerability in the PHP programming language that executes malicious code on web servers, security researchers said.
affects PHP only when it runs in a mode known as CGI, in which a web server parses HTTP requests and passes them to a PHP script for processing
https://censys.com/cve-2024-4577-pt2/
This configuration is extremely rare, with the exception of the XAMPP platform, which uses it by default
“Given that XAMPP is vulnerable by default, it’s reasonable to guess that most of the infected systems are running XAMPP,” the researchers said. This Censys query lists the infections that are explicitly affecting the platform.
/nosanitize
The researchers aren’t aware of any specific platforms other than XAMPP that have been compromised.