Appsecure logo

CVE-2024-11235: Critical Vulnerability in PHP

CVE-2024-11235 is a critical use-after-free vulnerability in PHP versions 8.3.* before 8.3.19 and 8.4.* before 8.4.5. It can lead to remote code execution, necessitating immediate patching.

CRITICALCVSS 9.2 · Published April 4, 2025

Not a customer? See how AppSecure simulates real world attacks to protect your infrastructure.

Speak to Experts

In recent disclosures, a critical vulnerability has been identified in PHP, specifically affecting versions 8.3.* prior to 8.3.19 and 8.4.* prior to 8.4.5. This vulnerability allows for a use-after-free condition, stemming from specific code sequences that involve the __set handler or the ??= operator combined with exceptions. If an attacker can manipulate the memory layout through specially crafted inputs, it could potentially lead to remote code execution.

This vulnerability has been assigned a CVSS score of 9.2, categorizing it as critical. The high severity is attributed to the potential impact on confidentiality, integrity, and availability, making it a significant risk for organizations utilizing affected PHP versions.

Currently, there are no known exploits for this vulnerability, but the critical nature of the flaw combined with its potential for remote code execution necessitates immediate attention from security teams. Organizations using vulnerable versions of PHP should prioritize patching to mitigate risks associated with this vulnerability.

Organizations should prioritize patching immediately.

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Latest CVEs. Recently published vulnerabilities from the NVD database.

View all vulnerabilities
CVE IDSeverity
CVE-2025-65418HIGH
CVE-2025-65417MEDIUM
CVE-2025-65416MEDIUM
CVE-2025-65415MEDIUM
CVE-2025-61314HIGH

Protect Your Business with Hacker-Focused Approach.