【要点】
◎HPの脆弱性はRCEや情報漏洩につながり、特にCVE-2024-4577が実際に悪用され日本企業も標的となる深刻な脅威
【要約】
PHPの脆弱性はリモートコード実行(RCE)や情報漏洩を引き起こす重大なリスクであり、特にCVE-2024-4577はWindows環境で認証不要のコマンド実行を可能にする欠陥として広範に悪用されている。実際に日本を含む企業が標的となり、バックドア設置やマルウェア感染が確認されている。JPEG処理やメモリ管理の欠陥など複数の問題も報告されており、迅速なパッチ適用と入力検証、WAF導入など多層防御が重要とされる。
【脆弱性内容】
| ★ |
CVE公開日 |
CVE登録日 |
CVE番号 |
NVD |
ベンダー |
CVSS v4 |
CVSS v3 |
CWE |
脆弱性 |
KEV公開日 |
備考 |
|---|---|---|---|---|---|---|---|---|---|---|---|
| ★ | 2019/10/28 | 2019/04/09 | CVE-2019-11043 | NVD | PHP | - | 9.8(NVD) 8.7(PHP) |
CWE-787 CWE-120 |
境界外書き込み 古典的バッファオーバーフロー |
2022/03/25 | PHP |
| ★ | 2024/06/09 | 2024/05/06 | CVE-2024-4577 | NVD | PHP | - | 9.8(PHP) |
CWE-78 | OSコマンドインジェクション | 2024/06/12 | PHP |
| 2025/03/30 | 2025/03/03 | CVE-2025-1861 | NVD | PHP Group | 6.3(PHP Group) |
9.8(NVD) |
CWE-131 | バッファサイズの計算の誤り | - | PHP | |
| 2025/03/30 | 2025/02/27 | CVE-2025-1734 | NVD | PHP Group | 6.3(PHP Group) |
5.3(NVD) |
CWE-20 | 不適切な入力確認 | - | PHP | |
| 2025/03/29 | 2025/02/11 | CVE-2025-1217 | NVD | PHP Group | 6.3(PHP Group) |
3.1(NVD) |
CWE-436 CWE-20 |
解釈の競合 不適切な入力確認 |
- | PHP | |
| 2025/03/30 | 2025/02/11 | CVE-2025-1219 | NVD | PHP Group | 6.3(PHP Group) |
5.3(NVD) |
CWE-1116 | 不正確なコメント | - | PHP | |
| 2025/03/30 | 2025/02/27 | CVE-2025-1736 | NVD | PHP Group | 6.3(PHP Group) |
7.3(NVD) |
CWE-20 | 不適切な入力確認 | - | PHP | |
| 2026/04/27 | 2026/04/27 | CVE-2026-42371 | NVD | uriparser | - | 5.1(Mitre) |
CWE-197 | 数値打ち切り誤差 | - | uriparser | |
| 2026/05/10 | 2026/04/20 | CVE-2026-6722 | NVD | PHP Group | 9.5(PHP Group) |
9.8(NVD) |
CWE-416 | 解放済みメモリの使用 | - | PHP | |
| 2026/05/10 | 2026/04/28 | CVE-2026-7261 | NVD | PHP Group | 6.3(PHP Group) |
9.8(NVD) |
CWE-416 | 解放済みメモリの使用 | PHP | ||
| 2026/05/10 | 2025/12/06 | CVE-2025-14179 | NVD | PHP Group | 7.4(PHP Group) |
9.8(NVD) |
CWE-89 | SQLインジェクション | - | PHP | |
| 2026/05/10 | 2026/04/11 | CVE-2026-6104 | NVD | PHP Group | 6.3(PHP Group) |
9.1(NVD) |
CWE-125 | 境界外読み取り | - | PHP | |
| 2026/05/10 | 2026/04/21 | CVE-2026-6735 | NVD | PHP Group | 7.3(PHP Group) |
6.1(NVD) |
CWE-79 | クロスサイトスクリプティング | - | PHP | |
| 2026/05/10 | 2026/04/28 | CVE-2026-7258 | NVD | PHP Group | 6.3(PHP Group) |
7.5(NVD) |
CWE-125 | 境界外読み取り | - | PHP | |
| 2026/05/10 | 2026/04/28 | CVE-2026-7259 | NVD | PHP Group | 2.1(PHP Group) |
6.5(NVD) |
CWE-476 | NULL ポインタデリファレンス | - | PHP | |
| 2026/05/10 | 2026/04/28 | CVE-2026-7262 | NVD | PHP Group | 2.9(PHP Group) |
7.5(NVD) |
CWE-476 | NULL ポインタデリファレンス | - | PHP | |
| 2026/05/10 | 2026/04/28 | CVE-2026-7263 | NVD | PHP Group | 6.3(PHP Group) |
7.5(NVD) |
CWE-404 CWE-835 |
リソースの不適切なシャットダウンおよびリリース 無限ループ |
- | PHP | |
| 2026/05/10 | 2026/04/30 | CVE-2026-7568 | NVD | PHP Group | 6.3(PHP Group) |
7.5(NVD) |
CWE-125 CWE-190 |
境界外読み取り 整数オーバーフローまたはラップアラウンド |
- | PHP |
【PHP】
◆CVE-2019-11043 (まとめ)
https://vul.hatenadiary.com/entry/CVE-2019-11043
◆CVE-2024-4577 (まとめ)
https://vul.hatenadiary.com/entry/CVE-2024-4577
【ニュース】
■2021年
◇2021年7月
◆Windows版が影響受ける深刻な脆弱性を解消した「PHP」新版 (Security NEXT, 2020/07/10)
http://www.security-next.com/116505
⇒ https://vul.hatenadiary.com/entry/2020/07/10/000000
◆PEARライブラリ「Archive_Tar」に脆弱性 - 「Drupal」などにも影響 (Security NEXT, 2021/07/27)
https://www.security-next.com/128450
⇒ https://vul.hatenadiary.com/entry/2021/07/27/000000_2
■2022年
◇2022年2月
◆「PHP」のセキュリティアップデートが公開 (Security NEXT, 2022/02/18)
https://www.security-next.com/134242
⇒ https://vul.hatenadiary.com/entry/2022/02/18/000000
■2024年
◇2024年6月
◆WindowsのPHPサーバに緊急の脆弱性、確認とアップデートを (マイナビニュース, 2024/06/10 15:23)
https://news.mynavi.jp/techplus/article/20240610-2962690/
⇒ https://vul.hatenadiary.com/entry/2024/06/10/000000_1
◇2024年8月
◆Hackers use PHP exploit to backdoor Windows systems with new malware (BleepingComputer, 2024/08/20 13:49)
[ハッカーがPHPの脆弱性を悪用し、Windowsシステムに新しいマルウェアをバックドアで侵入させる]
https://www.bleepingcomputer.com/news/security/hackers-use-php-exploit-to-backdoor-windows-systems-with-new-malware/
⇒ https://vul.hatenadiary.com/entry/2024/08/20/000000_2
◆PHPの脆弱性(CVE-2024-4577)を悪用してハッカーがバックドアを仕掛ける (セキュリティ対策Lab, 2024/08/21)
https://rocket-boys.co.jp/security-measures-lab/php-vulnerability-cve-2024-4577-backdoor-exploit/
⇒ https://vul.hatenadiary.com/entry/2024/08/21/000000_2
■2025年
◇2025年3月
◆ハッカーがPHPの脆弱性を悪用し、日本を標的にサイバー攻撃を実行(CVE-2024-4577) (セキュリティ対策Lab, 2025/03/10 )
https://rocket-boys.co.jp/security-measures-lab/hackers-exploit-php-cve-2024-4577-targeting-japan/
⇒ https://vul.hatenadiary.com/entry/2025/03/10/000000
◆PHPに複数の脆弱性、アップデートを (マイナビニュース, 2025/03/21 09:35)
https://news.mynavi.jp/techplus/article/20250321-3158218/
⇒ https://vul.hatenadiary.com/entry/2025/03/21/000000
◆PHPの重大な脆弱性を悪用する動きが活発化 日本企業への初期アクセス狙いか (ITmedia, 2025/03/22 07:00)
https://www.itmedia.co.jp/enterprise/articles/2503/22/news046.html
⇒ https://vul.hatenadiary.com/entry/2025/03/22/000000
◇2025年8月
◆PHP向けDBライブラリ「ADOdb」の「SQLite3ドライバ」に深刻な脆弱性 (Security NEXT, 2025/08/05)
https://www.security-next.com/173045
⇒ https://vul.hatenadiary.com/entry/2025/08/05/000000_1
◇2025年12月
◆「PHP」に複数脆弱性 - 修正版「同8.5.1」など公開 (Security NEXT, 2025/12/22)
https://www.security-next.com/178770
⇒ https://vul.hatenadiary.com/entry/2025/12/22/000000_4
■2026年
◇2026年5月
◆「PHP」に複数の「クリティカル」脆弱性 - アップデートで解消 (Security NEXT, 2026/05/15)
https://www.security-next.com/184498
⇒ https://vul.hatenadiary.com/entry/2026/05/15/000000_2
◆Crafted JPEGs Could Trigger PHP Memory Bugs for Exploitation (gbhackers., 2026/05/18)
[細工されたJPEGファイルがPHPのメモリバグを引き起こし、悪用される恐れがある]
https://gbhackers.com/crafted-jpegs-trigger-php-memory/
⇒ https://vul.hatenadiary.com/entry/2026/05/18/000000
◇2026年7月
◆「PHP」にセキュリティ更新 - 複数の脆弱性を修正 (Security NEXT, 2026/07/03)
https://www.security-next.com/186792
⇒ https://vul.hatenadiary.com/entry/2026/07/03/000000_3
【ブログ】
■2019年
◇2019年11月
◆【検証】PHPのコマンド実行の脆弱性を悪用する攻撃通信の検知 (CVE-2019-11043) (NRI NeoSOC, 2019/11/01)
https://www.secure-sketch.com/blog/verify-php-command-execution-vulnerability
⇒ https://vul.hatenadiary.com/entry/2019/11/01/000000_1
■2025年
◇2025年2月
◆【2025年2月版】PHP8.xの脆弱性情報一覧 (tane, 2025/02/21)
https://tane-creative.co.jp/column/6221/
⇒ https://vul.hatenadiary.com/entry/2025/02/21/000000_1
【公開情報】
◆PHPの脆弱性(CVE-2024-4577)を狙う攻撃について (IPA, 2024/07/05)
https://www.ipa.go.jp/security/security-alert/2024/alert_20240705.html
⇒ https://vul.hatenadiary.com/entry/2024/07/05/000000
【検索】
google:news: PHP
google:news: PHP 脆弱性
google: site:virustotal.com PHP
google: site:virustotal.com PHP 脆弱性
google: site:github.com PHP
google: site:github.com PHP 脆弱性
■Bing
https://www.bing.com/search?q=PHP
https://www.bing.com/search?q=PHP%20脆弱性
https://www.bing.com/news/search?q=PHP
https://www.bing.com/news/search?q=PHP%20脆弱性
https://twitter.com/search?q=%23PHP
https://twitter.com/search?q=%23PHP%20脆弱性
https://twitter.com/hashtag/PHP
https://twitter.com/hashtag/PHP%20脆弱性
■Exploit Code / PoC
https://www.exploit-db.com/search?q=PHP
https://www.exploit-db.com/search?q=PHP%20脆弱性
https://attackerkb.com/search?q=PHP
https://attackerkb.com/search?q=PHP%20脆弱性
【関連まとめ記事】
◆プログラミング言語 (まとめ)
https://vul.hatenadiary.com/entry/Programming_Language