SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2019-11043

PHP FastCGI Process Manager (FPM) Buffer Overflow Vulnerability

KEVCRITICAL 9.8EPSS 99.8%

Does this matter?

Known to be exploited in the wild (CISA KEV, CISA remediation deadline 15 April 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.

Description

In PHP versions 7.1.x below 7.1.33, 7.2.x below 7.2.24 and 7.3.x below 7.3.11 in certain configurations of FPM setup it is possible to cause FPM module to write past allocated buffers into the space reserved for FCGI protocol data, thus opening the possibility of remote code execution.

CVSS 3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
99.78% probability · 100th percentile
CISA KEV
Listed 25 March 2022 · due 15 April 2022 · used in ransomware campaigns
Weakness
CWE-120, CWE-787
Affected
php/php · canonical/ubuntu linux · debian/debian linux · fedoraproject/fedora · tenable/tenable.sc · redhat/software collections · redhat/enterprise linux · redhat/enterprise linux desktop · redhat/enterprise linux eus · redhat/enterprise linux eus compute node · redhat/enterprise linux for arm 64 · redhat/enterprise linux for arm 64 eus · redhat/enterprise linux for ibm z systems · redhat/enterprise linux for ibm z systems eus · redhat/enterprise linux for power big endian · redhat/enterprise linux for power big endian eus · redhat/enterprise linux for power little endian · redhat/enterprise linux for power little endian eus · redhat/enterprise linux for scientific computing · redhat/enterprise linux server · +3 more
Source
security@php.net

CISA notes

Apply updates per vendor instructions. https://nvd.nist.gov/vuln/detail/CVE-2019-11043

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.