Skip to content
COOEY

EXPOSURES › CVE-2019-11043

CVE-2019-11043

CRITICAL ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-03-25 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2019-11043 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 72/100 ransomwarerceexploited-in-wildunpatched

A buffer overflow vulnerability in PHP's FPM allowed for potential remote code execution and has been actively exploited in ransomware attacks, impacting systems using vulnerable PHP installations.

CVE-2019-11043 represents a critical buffer overflow in PHP's FPM, enabling potential remote code execution and linked to ransomware activity. DIB organizations using PHP must immediately assess their deployments, patch vulnerable versions, and review FPM configurations to prevent exploitation. Failure to address this vulnerability exposes systems to compromise and non-compliance with NIST 800-171 controls.

Shame score — The vulnerability's active exploitation in ransomware campaigns highlights a significant failure to maintain secure configurations and promptly apply security patches, demonstrating negligence.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

In some versions of PHP in certain configurations of FPM setup, it is possible to cause FPM module to write past allocated buffers allowing the possibility of remote code execution.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.