CVE-2019-11043
Act now ● On CISA KEV — actively exploited used in ransomware
Actively exploited — on the CISA KEV list.
CVSS base
—
EPSS — probability of exploitation (30 days)
99.8%
100.0th percentile
CISA KEV
Listed
Added 2022-03-25 · patch by 2022-04-15
Weakness / dates
—
Published — · modified —
Timeline
- 2022-03-25 — Added to CISA KEV (actively exploited)
- 2022-04-15 — CISA patch-by deadline
Description
In some versions of PHP in certain configurations of FPM setup, it is possible to cause FPM module to write past allocated buffers allowing the possibility of remote code execution.