EXPOSURES › CVE-2019-11043
CVE-2019-11043
CRITICAL ⌖ ON CISA KEV · EXPLOITEDA buffer overflow vulnerability in PHP's FPM allowed for potential remote code execution and has been actively exploited in ransomware attacks, impacting systems using vulnerable PHP installations.
CVE-2019-11043 represents a critical buffer overflow in PHP's FPM, enabling potential remote code execution and linked to ransomware activity. DIB organizations using PHP must immediately assess their deployments, patch vulnerable versions, and review FPM configurations to prevent exploitation. Failure to address this vulnerability exposes systems to compromise and non-compliance with NIST 800-171 controls.
Shame score — The vulnerability's active exploitation in ransomware campaigns highlights a significant failure to maintain secure configurations and promptly apply security patches, demonstrating negligence.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
In some versions of PHP in certain configurations of FPM setup, it is possible to cause FPM module to write past allocated buffers allowing the possibility of remote code execution.