# CVE-2024-1874

## Summary

- **CVE ID:** CVE-2024-1874
- **Severity:** CRITICAL
- **CVSS Score:** 9.4 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L)
- **CWE:** CWE-116
- **Published:** Apr 29, 2024
- **Last Modified:** Mar 13, 2026

## Description

In PHP versions 8.1.* before 8.1.28, 8.2.* before 8.2.18, 8.3.* before 8.3.5, when using proc_open() command with array syntax, due to insufficient escaping, if the arguments of the executed command are controlled by a malicious user, the user can supply arguments that would execute arbitrary commands in Windows shell.

## Affected Products

- PHP Group — PHP (8.1.*)
- PHP Group — PHP (8.2.*)
- PHP Group — PHP (8.3.*)

## References

- [CNA](https://github.com/php/php-src/security/advisories/GHSA-pc52-254m-w9w7)
- [CNA](http://www.openwall.com/lists/oss-security/2024/04/12/11)
- [CNA](https://security.netapp.com/advisory/ntap-20240510-0009/)
- [CNA](http://www.openwall.com/lists/oss-security/2024/06/07/1)
- [CNA](https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/PKGTQUOA2NTZ3RXN22CSAUJPIRUYRB4B/)
- [CNA](https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/W45DBOH56NQDRTOM2DN2LNA2FZIMC3PK/)
- [CVE](https://www.vicarius.io/vsociety/posts/command-injection-vulnerability-in-php-on-windows-systems-cve-2024-1874-and-cve-2024-5585)
- [CVE](https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/ZGWIK3HMBACERGB4TSBB2JUOMPYY2VKY/)
- [CVE](https://lists.fedoraproject.org/archives/list/package-announce@lists.fedoraproject.org/message/KJZK3X6B7FBE32FETDSMRLJXTFTHKWSY/)
- [CVE](https://www.kb.cert.org/vuls/id/123335)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 32.57%
- **EPSS Percentile:** 98.2

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._