Junglewise Threat Intelligence

CVE-2019-11043: PHP FastCGI Process Manager (FPM) Buffer Overflow Vulnerability

CVE-2019-11043 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2022-03-25

Technologies: PHP Group PHP. Vendors: PHP, PHP Group.

Executive brief

A buffer overflow vulnerability in the PHP FastCGI Process Manager (FPM) allows an attacker to write past allocated buffers into space reserved for FCGI protocol data. This flaw can be exploited in certain FPM configurations to achieve remote code execution.

Affected products

  • PHP Group PHP 7.1.x below 7.1.33, 7.2.x below 7.2.24, 7.3.x below 7.3.11

Timeline

  • 2019-10-24: disclosed: Initial bug report and patch development on PHP bug tracker.
  • 2022-03-25: kev added: Added to CISA's Known Exploited Vulnerabilities Catalog.
  • 2022-03-25: advisory: NVD publication date.
  • 2022-03-25: exploited: Confirmed exploited in the wild per CISA KEV.