PHP.EXE / Apache Win32 Arbitrary File Reading Vulnerability

Summary
A configuration vulnerability exists for PHP.EXE cgi running on Apache for Win32 platforms. It is reported that the installation text recommends configuration options in httpd.conf that create a security vulnerability, allowing arbitrary files to be read from the host running PHP. Remote users can directly execute the PHP binary: http://www.somehost.com/php/php.exe?c:\winnt\win.ini
Solution
Obtain the latest version from http://www.php.net
References