login
quiescence.eu
Naar inhoud

CVE-2019-11043

PHP FastCGI Process Manager (FPM) Buffer Overflow Vulnerability

n/a
CVSS
99.4%
EPSS (exploit prob.)
99.9%
EPSS percentile
Yes
Actively exploited
Yes
Ransomware use
2022-03-25
Added

Summary

In some versions of PHP in certain configurations of FPM setup, it is possible to cause FPM module to write past allocated buffers allowing the possibility of remote code execution.

Affected software

Vendor: PHP  ·  Product: FastCGI Process Manager (FPM)

Weakness types (CWE):

CWE-120

What to do

This vulnerability appears in CISA's Known Exploited Vulnerabilities catalog, meaning it is being exploited in the wild. Prioritize patching affected systems and verify exposure across your estate.

Related vulnerabilities in PHP

CVENameEPSSExploited
CVE-2012-1823 PHP-CGI Query String Parameter Vulnerability 100.0% Yes
CVE-2016-10033 PHPMailer Command Injection Vulnerability 99.7% Yes

Is your domain exposed?

Run a free, instant security report for any domain — exposure score, email auth, TLS and breach metadata.

Get your free report

All information is aggregated from public sources for awareness only and does not constitute an accusation or a security assessment. No personal data or credentials are published.