CVE-2019-11043 KEV EXPLOIT
8.7
HIGH · CVSS 3.1 · EPSS 99.8% (pctl 100)
Patch first
On CISA KEV — known exploited in the wild, due 2022-04-15.
Description
In PHP versions 7.1.x below 7.1.33, 7.2.x below 7.2.24 and 7.3.x below 7.3.11 in certain configurations of FPM setup it is possible to cause FPM module to write past allocated buffers into the space reserved for FCGI protocol data, thus opening the possibility of remote code execution.
Scoring
| CVSS | 8.7 (HIGH, v3.1) |
|---|---|
| Vector | CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N |
| EPSS | 99.78% — more likely to be exploited than 100% of all CVEs |
| Weakness | CWE-120 |
| On CISA KEV | yes — remediate by 2022-04-15 |
| Public exploit | yes |
| Published | 2019-10-28 |
| Last modified | 2026-06-17 |
CISA KEV
| Name | PHP FastCGI Process Manager (FPM) Buffer Overflow Vulnerability |
|---|---|
| Added | 2022-03-25 |
| Due | 2022-04-15 |
| Vendor / product | PHP / FastCGI Process Manager (FPM) |
| Ransomware use | known |
Affected (23)
| Vendor | Product |
|---|---|
| canonical | ubuntu linux |
| debian | debian linux |
| fedoraproject | fedora |
| php | php |
| redhat | enterprise linux |
| redhat | enterprise linux desktop |
| redhat | enterprise linux eus |
| redhat | enterprise linux eus compute node |
| redhat | enterprise linux for arm 64 |
| redhat | enterprise linux for arm 64 eus |
| redhat | enterprise linux for ibm z systems |
| redhat | enterprise linux for ibm z systems eus |
| redhat | enterprise linux for power big endian |
| redhat | enterprise linux for power big endian eus |
| redhat | enterprise linux for power little endian |
| redhat | enterprise linux for power little endian eus |
| redhat | enterprise linux for scientific computing |
| redhat | enterprise linux server |
| redhat | enterprise linux server aus |
| redhat | enterprise linux server tus |
| redhat | enterprise linux workstation |
| redhat | software collections |
| tenable | tenable.sc |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | PHP-FPM - Underflow Remote Code Execution (Metasploit) | 2020-03-09 |
| exploit-db | PHP-FPM + Nginx - Remote Code Execution | 2019-10-28 |
References
- http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00011.html
- http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00014.html
- http://packetstormsecurity.com/files/156642/PHP-FPM-7.x-Remote-Code-Execution.html
- http://seclists.org/fulldisclosure/2020/Jan/40
- https://access.redhat.com/errata/RHSA-2019:3286
- https://access.redhat.com/errata/RHSA-2019:3287
- https://access.redhat.com/errata/RHSA-2019:3299
- https://access.redhat.com/errata/RHSA-2019:3300
- https://access.redhat.com/errata/RHSA-2019:3724
- https://access.redhat.com/errata/RHSA-2019:3735
- https://access.redhat.com/errata/RHSA-2019:3736
- https://access.redhat.com/errata/RHSA-2020:0322
- https://bugs.php.net/bug.php?id=78599
- https://github.com/neex/phuip-fpizdam
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3W23TP6X4H7LB645FYZLUPNIRD5W3EPU/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FSNBUSPKMLUHHOADROKNG5GDWDCRHT5M/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/T62LF4ZWVV7OMMIZFO6IFO5QLZKK7YRD/
- https://seclists.org/bugtraq/2020/Jan/44
- https://security.netapp.com/advisory/ntap-20191031-0003/
- https://support.apple.com/kb/HT210919
→ the Explorer · watch your stack · NVD