CVE-2019-11043
Confirmed PUBLISHEDUnderflow in PHP-FPM can lead to RCE
Recommended Action
Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
At a Glance
In PHP versions 7.1.x below 7.1.33, 7.2.x below 7.2.24 and 7.3.x below 7.3.11 in certain configurations of FPM setup it is possible to cause FPM module to write past allocated buffers into the space reserved for FCGI protocol data, thus opening the possibility of remote code execution.
- CVE Published
- Oct 28, 2019
- Exploitation Reported
- Mar 25, 2022
- CVSS
- 8.7 High
- EPSS
- —
Affected Versions
| Vendor | Product | Version | Status |
|---|---|---|---|
| PHP |
PHP
|
7.1.x to < 7.1.33 |
Affected |
| PHP |
PHP
|
7.2.x to < 7.2.24 |
Affected |
| PHP |
PHP
|
7.3.x to < 7.3.11 |
Affected |
CVE References
- USN-4166-1 usn.ubuntu.com · Vendor Advisory https://usn.ubuntu.com/4166-1/
- DSA-4552 debian.org · Vendor Advisory https://www.debian.org/security/2019/dsa-4552
- DSA-4553 debian.org · Vendor Advisory https://www.debian.org/security/2019/dsa-4553
- USN-4166-2 usn.ubuntu.com · Vendor Advisory https://usn.ubuntu.com/4166-2/
- FEDORA-2019-4adc49a476 lists.fedoraproject.org · Vendor Advisory https://lists.fedoraproject.org/archives/list/package-announce%40list...
Show 22 more references
- RHSA-2019:3286 access.redhat.com · Vendor Advisory https://access.redhat.com/errata/RHSA-2019:3286
- RHSA-2019:3287 access.redhat.com · Vendor Advisory https://access.redhat.com/errata/RHSA-2019:3287
- RHSA-2019:3299 access.redhat.com · Vendor Advisory https://access.redhat.com/errata/RHSA-2019:3299
- RHSA-2019:3300 access.redhat.com · Vendor Advisory https://access.redhat.com/errata/RHSA-2019:3300
- FEDORA-2019-187ae3128d lists.fedoraproject.org · Vendor Advisory https://lists.fedoraproject.org/archives/list/package-announce%40list...
- FEDORA-2019-7bb07c3b02 lists.fedoraproject.org · Vendor Advisory https://lists.fedoraproject.org/archives/list/package-announce%40list...
- openSUSE-SU-2019:2441 lists.opensuse.org · Vendor Advisory http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00011...
- RHSA-2019:3724 access.redhat.com · Vendor Advisory https://access.redhat.com/errata/RHSA-2019:3724
- RHSA-2019:3735 access.redhat.com · Vendor Advisory https://access.redhat.com/errata/RHSA-2019:3735
- RHSA-2019:3736 access.redhat.com · Vendor Advisory https://access.redhat.com/errata/RHSA-2019:3736
- openSUSE-SU-2019:2457 lists.opensuse.org · Vendor Advisory http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00014...
- RHSA-2020:0322 access.redhat.com · Vendor Advisory https://access.redhat.com/errata/RHSA-2020:0322
- 20200129 APPLE-SA-2020-1-28-2 macOS Catalina 10.15.3, Security Update 2020-001 Mojave, Security Update 2020-001 High Sierra seclists.org · Mailing List https://seclists.org/bugtraq/2020/Jan/44
- 20200131 APPLE-SA-2020-1-28-2 macOS Catalina 10.15.3, Security Update 2020-001 Mojave, Security Update 2020-001 High Sierra seclists.org · Mailing List http://seclists.org/fulldisclosure/2020/Jan/40
- GitHub — neex/phuip-fpizdam github.com · CVE Record https://github.com/neex/phuip-fpizdam
- bugs.php.net/bug.php bugs.php.net · CVE Record https://bugs.php.net/bug.php?id=78599
- support.f5.com/csp/article/K75408500 support.f5.com · CVE Record https://support.f5.com/csp/article/K75408500?utm_source=f5support&...
- security.netapp.com/advisory/ntap-20191031-0003 security.netapp.com · CVE Record https://security.netapp.com/advisory/ntap-20191031-0003/
- synology.com/security/advisory/Synology_SA_19_36 synology.com · CVE Record https://www.synology.com/security/advisory/Synology_SA_19_36
- support.apple.com/kb/HT210919 support.apple.com · CVE Record https://support.apple.com/kb/HT210919
- packetstormsecurity.com/files/156642/PHP-FPM-7.x-Remote-Code-Executi... packetstormsecurity.com · CVE Record http://packetstormsecurity.com/files/156642/PHP-FPM-7.x-Remote-Code-E...
- tenable.com/security/tns-2021-14 tenable.com · CVE Record https://www.tenable.com/security/tns-2021-14
Recommended Actions
- Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
- Check enrichment artifacts for scanner coverage and available PoCs before rolling remediation validation.
- Use the Pro API to automate enrichment, telemetry, and workflow delivery for VM, SOC, and CTI pipelines.
Known Exploited Vulnerability Sources
Catalogues that list this CVE as a known exploited vulnerability.
Per-source evidence links for KEV attestations are available through the KEVIntel Pro API.
Learn about Pro API access| Source | Added |
|---|---|
| CISA First | 2022-03-25 00:00 UTC |
Scanner Artifacts
Nuclei and Metasploit references linked to this CVE.
| Scanner | Reference | Detected |
|---|---|---|
| Metasploit | https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/multi/http/php_fpm_rce.rb | Apr 28, 2025 |
Virtual Patch
Compensating WAF rules to help reduce exposure to this CVE. Rule content and deployable vendor exports are available with KEVIntel Enterprise.
KEVIntel does not currently have a virtual patch for this CVE. When available, KEVIntel virtual patches ship as deployable ModSecurity, Cloudflare, and AWS WAF rules.
Enterprise feature. Virtual patch rule content and deployable vendor exports (ModSecurity, Cloudflare, AWS WAF) are available to KEVIntel Enterprise users.
CVSS Scores
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:N
Exploitation Status
Exploited in the wild
Recorded 2022-03-25 00:00:00 UTC · CISA
Used in malware
Recorded 2022-03-25 00:00:00 UTC · CISA
Proof of concept available
Recorded 2019-10-23 13:32:14 UTC · GitHub
Weaknesses (CWE)
-
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
Scanner Integrations
| Scanner | Reference | Detected |
|---|---|---|
| Metasploit | https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/multi/http/php_fpm_rce.rb | Apr 28, 2025 |
Potential Proof of Concepts
These PoCs are unverified and could contain malware. Use at your own risk.
github · Created 2020-11-18 07:25:37 UTC · 4 stars
PHP-FPM Remote Command Execution Exploit
github · Created 2020-07-13 16:32:15 UTC · 0 stars
quick and dirty PHP RCE proof of concept
github · Created 2020-05-05 09:43:44 UTC · 12 stars
This repository provides a dockerized infrastructure and a python implementation of the CVE-2019-11043 exploit.
github · Created 2019-11-17 05:16:02 UTC · 1 stars
remote debug environment for CLion
github · Created 2019-11-11 11:29:54 UTC · 16 stars
Ladon POC Moudle CVE-2019-11043 (PHP-FPM + Ngnix)
github · Created 2019-11-06 15:44:47 UTC · 13 stars
CVE-2019-11043 PHP7.x RCE
github · Created 2019-11-06 14:53:13 UTC · 3 stars
CVE-2019-11043 && PHP7.x && RCE EXP
github · Created 2019-10-30 10:22:41 UTC · 7 stars
Docker image and commands to check CVE-2019-11043 vulnerability on nginx/php-fpm applications.
github · Created 2019-10-29 11:16:12 UTC · 5 stars
Python exp for CVE-2019-11043
github · Created 2019-10-28 11:09:06 UTC · 145 stars
(PoC) Python version of CVE-2019-11043 exploit by neex
github · Created 2019-10-24 12:32:02 UTC · 27 stars
github · Created 2019-10-24 09:12:38 UTC · 1 stars
github · Created 2019-10-24 09:09:01 UTC · 0 stars
github · Created 2019-10-24 05:28:41 UTC · 4 stars
PHP-FPM Remote Code Execution Vulnerability (CVE-2019-11043) POC in Python
github · Created 2019-10-23 13:34:28 UTC · 0 stars
Timeline
Key exploitation, disclosure, scanner coverage, and KEV attestation events for this CVE.
-
15:02 UTC about 1 year ago15:02 UTC · about 1 year ago
Metasploit module available
Exploit module available
-
00:00 UTC over 4 years ago00:00 UTC · over 4 years ago
Added to CISA KEV
Listed in the CISA Known Exploited Vulnerabilities catalog
-
00:00 UTC over 4 years ago00:00 UTC · over 4 years ago
First public exploitation report
Exploit observed in malware
-
14:19 UTC over 6 years ago14:19 UTC · over 6 years ago
CVE published
Vulnerability disclosed publicly
-
13:32 UTC over 6 years ago13:32 UTC · over 6 years ago
Public PoC available
Public proof-of-concept code published
-
00:00 UTC over 7 years ago00:00 UTC · over 7 years ago
CVE ID reserved
Identifier reserved by the CNA
Automate This Intelligence with the Pro API
Confidence scoring, exploit status, sensor telemetry, PoCs, scanner integrations, mentions, and tags are available programmatically for VM, SOC, and CTI workflows.
Pro API Example
GET /api/v2/pro/kevs/CVE-2019-11043
{
"cve_id": "CVE-2019-11043",
"title": "Underflow in PHP-FPM can lead to RCE",
"affected_vendor": "PHP",
"affected_product": "PHP",
"affected_versions": [
{ "vendor": "...", "product": "...", "status": "affected", "display_label": "..." }
],
"confidence": "Confirmed",
"cvss_score": 8.7,
"epss_score": null,
"exploit_status": {
"exploited_in_the_wild": true,
"active_exploitation_observed": false
},
"sensor_telemetry": { "...": "Pro API fields" },
"proof_of_concepts": [ "..." ],
"scanner_integrations": [ "..." ]
}