KEVIntel
8.7
CVSS
High

CVE-2019-11043

PUBLISHED

Underflow in PHP-FPM can lead to RCE

Exploited in the wild Used in malware Remote No user interaction
Vendor
PHP
Product
PHP
Published
Oct 28, 2019
EPSS

Description

In PHP versions 7.1.x below 7.1.33, 7.2.x below 7.2.24 and 7.3.x below 7.3.11 in certain configurations of FPM setup it is possible to cause FPM module to write past allocated buffers into the space reserved for FCGI protocol data, thus opening the possibility of remote code execution.

php cisa malware ransomware metasploit

CVSS scores

CVSS v3.1 8.7 High

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N

Exploitation status

Exploited in the wild

Recorded 2022-03-25 00:00:00 UTC · Source

Used in malware

Recorded 2022-03-25 00:00:00 UTC · Source

SSVC decision points

Exploitation
active
Automatable
No
Technical impact
total

References

Known exploited vulnerability sources

Catalogues that list this CVE as a known exploited vulnerability.

Source Added
CISA Mar 25, 2022

Scanner integrations

Potential proof of concepts

These PoCs are unverified and could contain malware. Use at your own risk.

php_fpm_rce

metasploit · Created Unknown

Metasploit module for CVE-2019-11043

jas9reet/CVE-2019-11043

github · Created 2022-03-04 16:25:16 UTC · 0 stars

CVE-2019-11043 LAB

lindemer/CVE-2019-11043

github · Created 2020-11-18 07:25:37 UTC · 4 stars

PHP-FPM Remote Command Execution Exploit

corifeo/CVE-2019-11043

github · Created 2020-07-13 16:32:15 UTC · 0 stars

quick and dirty PHP RCE proof of concept

kriskhub/CVE-2019-11043

github · Created 2020-05-05 09:43:44 UTC · 12 stars

This repository provides a dockerized infrastructure and a python implementation of the CVE-2019-11043 exploit.

moniik/CVE-2019-11043_env

github · Created 2019-11-17 05:16:02 UTC · 1 stars

remote debug environment for CLion

k8gege/CVE-2019-11043

github · Created 2019-11-11 11:29:54 UTC · 16 stars

Ladon POC Moudle CVE-2019-11043 (PHP-FPM + Ngnix)

0th3rs-Security-Team/CVE-2019-11043

github · Created 2019-11-06 15:44:47 UTC · 13 stars

CVE-2019-11043 PHP7.x RCE

MRdoulestar/CVE-2019-11043

github · Created 2019-11-06 14:53:13 UTC · 3 stars

CVE-2019-11043 && PHP7.x && RCE EXP

ypereirareis/docker-CVE-2019-11043

github · Created 2019-10-30 10:22:41 UTC · 7 stars

Docker image and commands to check CVE-2019-11043 vulnerability on nginx/php-fpm applications.

huowen/CVE-2019-11043

github · Created 2019-10-29 11:16:12 UTC · 5 stars

Python exp for CVE-2019-11043

theMiddleBlue/CVE-2019-11043

github · Created 2019-10-28 11:09:06 UTC · 145 stars

(PoC) Python version of CVE-2019-11043 exploit by neex

akamajoris/CVE-2019-11043-Docker

github · Created 2019-10-24 12:32:02 UTC · 27 stars

fairyming/CVE-2019-11043

github · Created 2019-10-24 09:12:38 UTC · 1 stars

ianxtianxt/CVE-2019-11043

github · Created 2019-10-24 09:09:01 UTC · 0 stars

AleWong/PHP-FPM-Remote-Code-Execution-Vulnerability-CVE-2019-11043-

github · Created 2019-10-24 05:28:41 UTC · 4 stars

PHP-FPM Remote Code Execution Vulnerability (CVE-2019-11043) POC in Python

jas502n/CVE-2019-11043

github · Created 2019-10-23 23:26:57 UTC · 104 stars

php-fpm+Nginx RCE

tinker-li/CVE-2019-11043

github · Created 2019-10-23 13:34:28 UTC · 0 stars

B1gd0g/CVE-2019-11043

github · Created 2019-10-23 13:32:14 UTC · 0 stars

CVE-2019-11043

Timeline

  • CVE ID Reserved

  • CVE Published to Public

  • Exploit Used in Malware

  • Added to KEVIntel

  • Detected by Metasploit