EXPOSURES › CVE-2019-0211
CVE-2019-0211
HIGH ⌖ ON CISA KEV · EXPLOITEDApache HTTP Server allowed privilege escalation to root via scoreboard manipulation, enabling attackers to execute arbitrary code as the parent process.
The vulnerability allowed attackers to escalate privileges from less-privileged child processes to the root-level parent process, enabling arbitrary code execution. DIB organizations must ensure Apache HTTP Server is patched to prevent attackers from gaining root access and compromising web applications. This failure is avoidable through timely patching and highlights the risk of unpatched software in production environments.
Shame score — A privilege escalation vulnerability in a widely deployed web server that allows attackers to execute code as root is highly avoidable through patching and represents a significant security failure.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Apache HTTP Server, with MPM event, worker or prefork, code executing in less-privileged child processes or threads (including scripts executed by an in-process scripting interpreter) could execute code with the privileges of the parent process (usually root) by manipulating the scoreboard.
"Apache HTTP Server, with MPM event, worker or prefork, code executing in less-privileged child processes or threads (including scripts executed by an in-process scripting interpreter) could execute code with the privileges of the parent process (usually root) by manipulating the scoreboard."