CVE detail
CVE-2019-11043
In PHP versions 7.1.x below 7.1.33, 7.2.x below 7.2.24 and 7.3.x below 7.3.11 in certain configurations of FPM setup it is possible to cause FPM module to write past allocated buffers into the space reserved for FCGI protocol data, thus opening the possibility of remote code execution.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 24.0 · diversity 13.0 · KEV 25.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
10 source links · newest first
New CISA guidance details cyber threats and risks to healthcare and public health organizations and recommends mitigations.
newswww.securityweek.comNov 20, 2023, 2:52 PM- 27th June – Threat Intelligence ReportCheck Point Research
For the latest discoveries in cyber research for the week of 27th June, please download our Threat Intelligence Bulletin. Top Attacks and Breaches A Chinese APT group dubbed Bronze Starlight (APT10) is attempting to use ransomware attacks mainly against Japanese companies, only as decoy to hide its true objectives – intellectual property theft and cyber […]
vendorresearch.checkpoint.comJun 27, 2022, 12:47 PM Taiwanese company QNAP is addressing a critical PHP vulnerability that could be exploited to achieve remote code execution. Taiwanese vendor QNAP is addressing a critical PHP vulnerability, tracked as CVE-2019-11043 (CVSS score 9.8 out of 10), that could be exploited to achieve remote code execution. In certain configurations of FPM setup it is possible to […]
newssecurityaffairs.comJun 23, 2022, 10:48 AM- 18th November – Threat Intelligence BulletinCheck Point Research
For the latest discoveries in cyber research for the week of 18th November 2019, please download our Threat Intelligence Bulletin. Top attacks and Breaches The Mexican state-owned oil company Petróleos Mexicanos (Pemex) has been infected with the DoppelPaymer ransomware in an incident that reportedly affected less than 5% of its network. DoppelPaymer is a forked […]
vendorresearch.checkpoint.comNov 18, 2019, 1:04 PM NextCry is a new ransomware that was spotted by researchers while encrypting data on Linux servers in the wild. Security experts spotted new ransomware dubbed NextCry that targets the clients of the NextCloud file sync and share service. The name comes from the extensions the ransomware appends to the filenames of encrypted files. The malicious code targets Nextcloud […]
newssecurityaffairs.comNov 18, 2019, 8:02 AM- Week in review: Keeping up with ransomware, critical PHP RCE exploited, DevOps firewallHelp Net Security
Here’s an overview of some of last week’s most interesting news and articles: Leading domain name registrars suffered data breach Web technology company Web.com and its subsidiaries – domain name registrars Register.com and Network Solutions – have suffered a data breach. Exploring the benefits of cybersecurity certification In this interview, Tony Vizza, Director of Cybersecurity Advocacy APAC, (ISC)2, talks about the benefits of earning a cybersecurity certification, the most common misconceptions related to getting certified, … More →
newswww.helpnetsecurity.comNov 3, 2019, 3:00 PM - 28th October – Threat Intelligence BulletinCheck Point Research
For the latest discoveries in cyber research for the week of 28th October 2019, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Procter & Gamble’s site, ‘First Aid Beauty’ has been infected by a Magecart credit card skimmer for the past five months. The heavily obfuscated and encrypted skimmer specifically targeted US […]
vendorresearch.checkpoint.comOct 28, 2019, 2:21 PM - PHP RCE flaw actively exploited to pop NGINX serversHelp Net Security
A recently patched vulnerability (CVE-2019-11043) in PHP is being actively exploited by attackers to compromise NGINX web servers, threat intelligence firm Bad Packets has confirmed. For a successful exploitation, target servers must have the PHP-FPM (FastCGI Process Manager) feature enabled, but that combination is not as uncommon as initially believed. About CVE-2019-11043 The flaw was discovered by Wallarm researcher Andrew Danau during a Capture The Flag contest that took place in September 2019. The PHP … More →
newswww.helpnetsecurity.comOct 28, 2019, 12:24 PM - Security Affairs newsletter Round 237Security Affairs
A new round of the weekly newsletter arrived! The best news of the week with Security Affairs Hi folk, let me inform you that I suspended the newsletter service, anyway I’ll continue to provide you a list of published posts every week through the blog. Fake UpdraftPlus WordPress Plugins used to backdoor sites TA505 cybercrime […]
newssecurityaffairs.comOct 27, 2019, 11:12 AM asty PHP7 remote code execution bug exploited in the wild Experts warn of a remote code execution vulnerability in PHP7, tracked as CVE-2019-11043, has been exploited in attacks in the wild. A remote code execution vulnerability in PHP7, tracked as CVE-2019-11043, has been exploited in attacks in the wild. On October 22, the security expert […]
newssecurityaffairs.comOct 26, 2019, 3:07 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2021-44142CVSS 8.8 · High
The Samba vfs_fruit module uses extended file attributes (EA, xattr) to provide "...enhanced compatibility with Apple SMB clients and interoperability with a Netatalk 3 AFP filese…
- CVE-2021-40438CVSS 9.0 · Critical
A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier.
- CVE-2023-3899CVSS 7.8 · High
A vulnerability was found in subscription-manager that allows local privilege escalation due to inadequate authorization. The D-Bus interface com.redhat.RHSM1 exposes a significan…
- CVE-2020-25717CVSS 8.1 · High
A flaw was found in the way Samba maps domain users to local users. An authenticated attacker could use this flaw to cause possible privilege escalation.
- CVE-2016-2124CVSS 5.9 · Medium
A flaw was found in the way samba implemented SMB1 authentication. An attacker could use this flaw to retrieve the plaintext password sent over the wire even if Kerberos authentic…
- CVE-2021-4034CVSS 7.8 · High
A local privilege escalation vulnerability was found on polkit's pkexec utility. The pkexec application is a setuid tool designed to allow unprivileged users to run commands as pr…