CVE-2019-11043
published 2019-10-28CVE-2019-11043: In PHP versions 7.1.x below 7.1.33, 7.2.x below 7.2.24 and 7.3.x below 7.3.11 in certain configurations of FPM setup it is possible to cause FPM module to…
PriorityP1100critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
KEVITWEXPLOITRansomwareInitial access
CISA Known Exploited Vulnerabilitydue 2022-04-15
Exploited in the wild
EPSS
99.47%
99.9th percentile
In PHP versions 7.1.x below 7.1.33, 7.2.x below 7.2.24 and 7.3.x below 7.3.11 in certain configurations of FPM setup it is possible to cause FPM module to write past allocated buffers into the space reserved for FCGI protocol data, thus opening the possibility of remote code execution.
Affected
70 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| php | php | >= 7.1.0 < 7.1.33 | 7.1.33 |
| php | php | >= 7.1.x < 7.1.33 | 7.1.33 |
| php | php | >= 7.2.0 < 7.2.24 | 7.2.24 |
| php | php | >= 7.2.x < 7.2.24 | 7.2.24 |
| php | php | >= 7.3.0 < 7.3.11 | 7.3.11 |
| php | php | >= 7.3.x < 7.3.11 | 7.3.11 |
| php5 | php5 | >= 0 < 5.5.9+dfsg-1ubuntu4.29+esm6 | 5.5.9+dfsg-1ubuntu4.29+esm6 |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_eus | — | — |
Detection & IOCsextracted from sources · hover to see the quote
urlGET /index.php/PHP_VALUE%0Asession.auto_start=1;;;?QQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQQ HTTP/1.1↗
- →Scope detection to NGINX servers with PHP-FPM enabled. The fastcgi_split_path_info directive must be present. Apache and other servers are not affected. ↗
- →CVE-2019-11043 was actively exploited in the wild to deploy NextCry ransomware against Linux NextCloud instances. Correlate PHP-FPM RCE indicators with NextCry ransomware artifacts on Linux systems. ↗
- →Attackers run the initial exploit request in a loop to infect as many PHP-FPM workers as possible before sending the RCE trigger. Detect repeated identical malformed requests to the same PHP endpoint in rapid succession. ↗
- →The X-Powered-By response header value 'PHP/7.1.33dev' (or any 7.1.x < 7.1.33, 7.2.x < 7.2.24, 7.3.x < 7.3.11) on an NGINX server indicates a potentially vulnerable target. ↗
- ·The vulnerability is only exploitable on NGINX servers with PHP-FPM enabled. Apache and other web servers are not affected, even with vulnerable PHP versions. ↗
- ·The RCE trigger request (?a=<cmd>) only executes if it is processed by an already-infected PHP-FPM worker. Detection of the trigger alone without the prior infection loop may produce false negatives. ↗
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.5HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
osv9.8CRITICAL
vulncheck8.7HIGH
cisa9.8CRITICAL
vendor_redhat8.7HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-6qjm-m8fp-j2mm: In PHP versions 7
ghsa_unreviewed·2022-05-24
CVE-2019-11043 [HIGH] CWE-120 GHSA-6qjm-m8fp-j2mm: In PHP versions 7
In PHP versions 7.1.x below 7.1.33, 7.2.x below 7.2.24 and 7.3.x below 7.3.11 in certain configurations of FPM setup it is possible to cause FPM module to write past allocated buffers into the space reserved for FCGI protocol data, thus opening the possibility of remote code execution.
OSV
CVE-2019-11043: In PHP versions 7
osv·2019-10-24·CVSS 9.8
CVE-2019-11043 [CRITICAL] CVE-2019-11043: In PHP versions 7
In PHP versions 7.1.x below 7.1.33, 7.2.x below 7.2.24 and 7.3.x below 7.3.11 in certain configurations of FPM setup it is possible to cause FPM module to write past allocated buffers into the space reserved for FCGI protocol data, thus opening the possibility of remote code execution.
Kernel
powerpc/tm: Fix oops on sigreturn on systems without TM
kernel_security·2019-07-19
CVE-2019-13648 powerpc/tm: Fix oops on sigreturn on systems without TM
powerpc/tm: Fix oops on sigreturn on systems without TM
On systems like P9 powernv where we have no TM (or P8 booted with
ppc_tm=off), userspace can construct a signal context which still has
the MSR TS bits set. The kernel tries to restore this context which
results in the following crash:
Unexpected TM Bad Thing exception at c0000000000022fc (msr 0x8000000102a03031) tm_scratch=800000020280f033
Oops: Unrecoverable exception, sig: 6 [#1]
LE PAGE_SIZE=64K MMU=Hash SMP NR_CPUS=2048 NUMA pSeries
Modules linked in:
CPU: 0 PID: 1636 Comm: sigfuz Not tainted 5.2.0-11043-g0a8ad0ffa4 #69
NIP: c0000000000022fc LR: 00007fffb2d67e48 CTR: 0000000000000000
REGS: c00000003fffbd70 TRAP: 0700 Not tainted (5.2.0-11045-g7142b497d8)
MSR: 8000000102a03031 CR: 42004242 XER: 00000000
CFAR: c0000000000022e0 IR
VulnCheck
PHP FastCGI Process Manager (FPM) Buffer Overflow Vulnerability
vulncheck·2019·CVSS 8.7
CVE-2019-11043 [HIGH] CWE-120 PHP FastCGI Process Manager (FPM) Buffer Overflow Vulnerability
PHP FastCGI Process Manager (FPM) Buffer Overflow Vulnerability
In some versions of PHP in certain configurations of FPM setup, it is possible to cause FPM module to write past allocated buffers allowing the possibility of remote code execution.
Affected: PHP FastCGI Process Manager (FPM)
Required Action: Apply updates per vendor instructions.
Known Ransomware Campaign Use: Known
Exploitation References: https://www.f5.com/labs/articles/threat-intelligence/vulnerabilities-exploits-and-malware-driving-attack-campaigns-in-november-2019; https://www.f5.com/labs/articles/threat-intelligence/vulnerabilities--exploits--and-malware-driving-attack-campaigns-in-december-2019; https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json; https://thedfirreport.com/2023/12/
CISA ICS
Festo Didactic SE MES PC
cisa_ics·2026-01-27·CVSS 7.5
[HIGH] Festo Didactic SE MES PC
ICS Advisory
##
Festo Didactic SE MES PC
Release DateJanuary 27, 2026
Alert CodeICSA-26-027-02
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
View CSAF
## Summary
MES PCs shipped with Windows 10 come pre-installed with XAMPP. XAMPP is a bundle of third-party open-source applications including the Apache HTTP Server, the MariaDB database and more. From time to time, vulnerabilities in these applications are discovered. These are fixed in newer versions of XAMPP by updating the bundled applications. MES PCs shipped with Windows 10 include a copy of XAMPP which contains around 140 such vulnerabilities listed in this advisory. They can be fixed by replacing XAMPP with Festo Didactic's Factory Control Panel application.
The
CISA
PHP FastCGI Process Manager (FPM) Buffer Overflow Vulnerability
cisa·2022-03-25·CVSS 9.8
CVE-2019-11043 [CRITICAL] CWE-120 PHP FastCGI Process Manager (FPM) Buffer Overflow Vulnerability
Vulnerability: PHP FastCGI Process Manager (FPM) Buffer Overflow Vulnerability
Affected: PHP FastCGI Process Manager (FPM)
In some versions of PHP in certain configurations of FPM setup, it is possible to cause FPM module to write past allocated buffers allowing the possibility of remote code execution.
Required Action: Apply updates per vendor instructions.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2019-11043
Remediation Due Date: 2022-04-15
Ubuntu
PHP vulnerability
vendor_ubuntu·2019-10-29
CVE-2019-11043 PHP vulnerability
Title: PHP vulnerability
Summary: PHP could be made to run programs if it received specially crafted network
traffic.
USN-4166-1 fixed a vulnerability in PHP. This update provides
the corresponding update for Ubuntu 12.04 ESM and Ubuntu 14.04 ESM.
Original advisory details:
It was discovered that PHP incorrectly handled certain paths when being
used in FastCGI configurations. A remote attacker could possibly use this
issue to execute arbitrary code.
Instructions: In general, a standard system update will make all the necessary changes.
Ubuntu
PHP vulnerability
vendor_ubuntu·2019-10-28
CVE-2019-11043 PHP vulnerability
Title: PHP vulnerability
Summary: PHP could be made to run programs if it received specially crafted network
traffic.
It was discovered that PHP incorrectly handled certain paths when being
used in FastCGI configurations. A remote attacker could possibly use this
issue to execute arbitrary code.
Instructions: In general, a standard system update will make all the necessary changes.
Red Hat
php: underflow in env_path_info in fpm_main.c
vendor_redhat·2019-10-24·CVSS 8.7
CVE-2019-11043 [HIGH] CWE-787 php: underflow in env_path_info in fpm_main.c
php: underflow in env_path_info in fpm_main.c
In PHP versions 7.1.x below 7.1.33, 7.2.x below 7.2.24 and 7.3.x below 7.3.11 in certain configurations of FPM setup it is possible to cause FPM module to write past allocated buffers into the space reserved for FCGI protocol data, thus opening the possibility of remote code execution.
Statement: This issue only affects instances running php-fpm under nginx server software as environment paths and parameters are handled by different code pieces depending on the server php-fpm is running under. The code where this issue is found is used exclusively when php-fpm detects the request came through an nginx server.
Red Hat Product Security team rated this issue as having a Critical security impact as an attacker may take advantage from the existing
Suricata
ET WEB_SERVER Possible PHP Remote Code Execution CVE-2019-11043 PoC (Inbound)
suricata·2019-10-23·CVSS 8.7
CVE-2019-11043 [HIGH] ET WEB_SERVER Possible PHP Remote Code Execution CVE-2019-11043 PoC (Inbound)
ET WEB_SERVER Possible PHP Remote Code Execution CVE-2019-11043 PoC (Inbound)
Rule: alert http any any -> $HTTP_SERVERS any (msg:"ET WEB_SERVER Possible PHP Remote Code Execution CVE-2019-11043 PoC (Inbound)"; flow:established,to_server; http.uri; content:"|25|OA"; nocase; content:"=/bin/sh+-c+'"; nocase; distance:0; fast_pattern; reference:url,github.com/neex/phuip-fpizdam; reference:url,github.com/vulhub/vulhub/tree/master/php/CVE-2019-11043; reference:cve,2019-11043; classtype:web-application-attack; sid:2028895; rev:3; metadata:affected_product PHP, attack_target Web_Server, created_at 2019_10_23, cve CVE_2019_11043, deployment Perimeter, confidence Medium, signature_severity Major, tag CISA_KEV, tag Description_Generated_By_Proofpoint_Nexus, updated_at 2020_10_20, mitre_tactic_id TA0
Exploit-DB
PHP-FPM - Underflow Remote Code Execution (Metasploit)
exploitdb·2020-03-09
CVE-2019-11043 PHP-FPM - Underflow Remote Code Execution (Metasploit)
PHP-FPM - Underflow Remote Code Execution (Metasploit)
---
##
# This module requires Metasploit: https://metasploit.com/download
# Current source: https://github.com/rapid7/metasploit-framework
##
class MetasploitModule 'PHP-FPM Underflow RCE',
'Description' => %q(
This module exploits an underflow vulnerability in versions 7.1.x
below 7.1.33, 7.2.x below 7.2.24 and 7.3.x below 7.3.11 of PHP-FPM on
Nginx. Only servers with certains Nginx + PHP-FPM configurations are
exploitable. This is a port of the original neex's exploit code (see
refs.). First, it detects the correct parameters (Query String Length
and custom header length) needed to trigger code execution. This step
determines if the target is actually vulnerable (Check method). Then,
the exploit sets a series of PHP INI directives
Exploit-DB
PHP-FPM + Nginx - Remote Code Execution
exploitdb·2019-10-28·CVSS 8.7
CVE-2019-11043 [HIGH] PHP-FPM + Nginx - Remote Code Execution
PHP-FPM + Nginx - Remote Code Execution
---
# PHuiP-FPizdaM
## What's this
This is an exploit for a bug in php-fpm (CVE-2019-11043). In certain nginx + php-fpm configurations, the bug is possible to trigger from the outside. This means that a web user may get code execution if you have vulnerable config (see [below](#the-full-list-of-preconditions)).
## What's vulnerable
If a webserver runs nginx + php-fpm and nginx have a configuration like
```
location ~ [^/]\.php(/|$) {
...
fastcgi_split_path_info ^(.+?\.php)(/.*)$;
fastcgi_param PATH_INFO $fastcgi_path_info;
fastcgi_pass php:9000;
...
}
```
which also lacks any script existence checks (like `try_files`), then you can probably hack it with this sploit.
#### The full list of preconditions
1. Nginx + php-fpm, `location ~ [^/]\.ph
Metasploit
PHP-FPM Underflow RCE
metasploit
PHP-FPM Underflow RCE
PHP-FPM Underflow RCE
This module exploits an underflow vulnerability in versions 7.1.x below 7.1.33, 7.2.x below 7.2.24 and 7.3.x below 7.3.11 of PHP-FPM on Nginx. Only servers with certains Nginx + PHP-FPM configurations are exploitable. This is a port of the original neex's exploit code (see refs.). First, it detects the correct parameters (Query String Length and custom header length) needed to trigger code execution. This step determines if the target is actually vulnerable (Check method). Then, the exploit sets a series of PHP INI directives to create a file locally on the target, which enables code execution through a query string parameter. This is used to execute normal payload stagers. Finally, this module does some cleanup by killing local PHP-FPM workers (those are spawned aut
Dfir Report
Lets Open(Dir) Some Presents: An Analysis of a Persistent Actor’s Activity
blogs_dfir_report·2023-12-18
Lets Open(Dir) Some Presents: An Analysis of a Persistent Actor’s Activity
From a Single Click: How Lunar Spider Enabled a Near Two-Month Intrusion Read More
- dragonforce Blurring the Lines: Intrusion Shows Connection With Three Major Ransomware Gangs Read More
Services Overview
Threat Hunting
-
Integration
CTI Program Advisory
Incident Response Playbook
About us
Contact Us
Collaboration
Careers
Analysts
Access DFIR Labs
Get in Touch
Public Reports
Products Overview
Threat intel Overview
Threat Feed
Private DFIR Reports
All Intel
Active Defense
DFIR Labs
Case Artifacts
Detection Pack
AI Training Ground
Service Overview
Threat Hunting
Integration
CTI Program Advisory
Incident Response Playbook
Company Overview
About us
Contact Us
Careers
Analyst
SQL Brute Force Leads to BlueSky Ransomware
From OneNote to RansomNote: An Ice Col
Checkpoint
27th June – Threat Intelligence Report
blogs_checkpoint·2022-06-27·CVSS 9.8
CVE-2022-29499 [CRITICAL] 27th June – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 27th June – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 27th June, please download our Threat Intelligence Bulletin .
Top Attacks and Breaches
A Chinese APT group dubbed Bronze Starlight (APT10) is attempting to use ransomware attacks mainly against Japanese companies, only as decoy to hide its true objectives – intellectual property theft and cyber espionage.
Check Point Threat Emulation provides protection against this threat (Ransomware.Win.Pandora.A)
The Russian
Checkpoint
18th November – Threat Intelligence Bulletin
blogs_checkpoint·2019-11-18
CVE-2019-11043 18th November – Threat Intelligence Bulletin
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 18th November – Threat Intelligence Bulletin
For the latest discoveries in cyber research for the week of 18th November 2019, please download our Threat Intelligence Bulletin .
Top attacks and Breaches
The Mexican state-owned oil company Petróleos Mexicanos (Pemex) has been infected with the DoppelPaymer ransomware in an incident that reportedly affected less than 5% of its network. DoppelPaymer is a forked version of the BitPaymer ransomware.
Check Point Anti-Virus and Anti-Ransomware provide protection agains
Qualys
CVE‑2019‑11043: PHP Remote Code Execution Exploit | Qualys
blogs_qualys·2019-10-30·CVSS 8.7
CVE-2019-11043 [HIGH] CVE‑2019‑11043: PHP Remote Code Execution Exploit | Qualys
#### Table of Contents
- Vulnerability Scope & Details
- Exploitation
- Detecting the Vulnerability with Qualys WAS
- Protection with Qualys WAF
- Solution
- Credits
Certain versions of PHP 7 running on NGINX with php-fpm enabled can be vulnerable to the remote code execution vulnerability CVE-2019-11043.
Given the simplicity of the exploit, all web servers using the vulnerable version of PHP should be upgraded to non-vulnerable PHP versions as soon as possible. Because the vulnerability is limited to specific configurations, the number of vulnerable installations is smaller than it might be.
Qualys Web Application Scanning (WAS) will test for this vulnerability as long as QIDs 150270 and 150271 are included in your scan. We recommend organizations immediately remediate all systems tha
Qualys
PHP Remote Code Execution Vulnerability (CVE-2019-11043)
blogs_qualys·2019-10-30·CVSS 8.7
CVE-2019-11043 [HIGH] PHP Remote Code Execution Vulnerability (CVE-2019-11043)
## Table of Contents
Vulnerability Scope & Details
Exploitation
Detecting the Vulnerability with Qualys WAS
Protection with Qualys WAF
Solution
Credits
Certain versions of PHP 7 running on NGINX with php-fpm enabled can be vulnerable to the remote code execution vulnerability CVE-2019-11043 .
Given the simplicity of the exploit, all web servers using the vulnerable version of PHP should be upgraded to non-vulnerable PHP versions as soon as possible. Because the vulnerability is limited to specific configurations, the number of vulnerable installations is smaller than it might be.
Qualys Web Application Scanning (WAS) will test for this vulnerability as long as QIDs 150270 and 150271 are included in your scan. We recommend organizations immediately remediate all systems that are vu
Checkpoint
28th October – Threat Intelligence Bulletin
blogs_checkpoint·2019-10-28
CVE-2019-11478 28th October – Threat Intelligence Bulletin
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 28th October – Threat Intelligence Bulletin
For the latest discoveries in cyber research for the week of 28th October 2019, please download our Threat Intelligence Bulletin .
TOP ATTACKS AND BREACHES
Procter & Gamble’s site, ‘First Aid Beauty’ has been infected by a Magecart credit card skimmer for the past five months. The heavily obfuscated and encrypted skimmer specifically targeted US victims using Windows systems. Earlier this week the FBI has issued a warning advising SMSB to beware of E-skimming attacks.
Tenable
CVE-2019-11043: Vulnerability in PHP-FPM Could Lead to Remote Code Execution on nginx
blogs_tenable·2019-10-24·CVSS 8.7
[HIGH] CVE-2019-11043: Vulnerability in PHP-FPM Could Lead to Remote Code Execution on nginx
## Cloud Exposure
Tenable Cloud Security (CNAPP) Request a demo
Tenable Cloud Vulnerability Management Request a demo
Tenable CIEM Request a demo
Secure your cloud
## Vulnerability Exposure
Tenable Vulnerability Management Try for free
Tenable Security Center Request a demo
Tenable Web App Scanning Try for free
Tenable Patch Management Request a demo
Tenable Enclave Security Request a demo
Tenable Attack Surface Management Request a demo
Tenable Nessus Try for free
## AI Exposure
Tenable AI Exposure Request a demo
## OT/IoT Exposure
Tenable OT Security Request a demo
## Identity Exposure
Tenable Identity Exposure Request a demo
## Business needs
Active Directory
AI Security Posture Management (AI-SPM)
AWS security
Azure security
Cloud Security Posture Man
CTF
solver / README
ctf_writeups·2024·CVSS 8.7
CVE-2019-11043 [HIGH] solver / README
# Timeworn Code Writeup
when we first visit the webpage we notice there is nothing on the screen except for the **Hello Hackers** and the hint in the bottom right saying **made with nginx + php-fpm configurations.** , so the good hackers we are we run to google asking for `nginx and php-fpm vulnerabilities` and evidently the first result we get tells us that there is a registered vulnerability `CVE-2019-11043`
> CVE stands for Common Vulnerabilities and Exposures. CVE is a glossary that classifies vulnerabilities. The glossary analyzes vulnerabilities and then uses the Common Vulnerability Scoring System (CVSS) to evaluate the threat level of a vulnerability.
after getting our vulnerability we start searching for a **POC** (proof of concept) or an **exploit**
after some searching i stum
CTF
Static / README
ctf_writeups
Static / README
# Static - HackTheBox - Writeup
Linux, 30 Base Points, Medium
## Machine
## TL;DR
To solve this machine, we begin by enumerating open services using ```namp``` – finding ports ```22```, ```2222``` and ```8080```.
***User***: On ```robots.txt``` file we found two URL's [/vpn] and [ftp_uploads], Download ```db.sql.gz``` file from the FTP, Fixed the corrupted file using ```fixgz```, On the fixed file we found the hash of the admin credentials to [/vpn] portal, Create OTP and log in as admin to the [/vpn] portal, From the VPN portal we download the ```web.ovpn``` file, Using that, We can access to the [web] website, Found file ```info.php``` which lead us to PHPInfo page, We found there ```Xdebug``` PHP extension which lead us to RCE, Using that we get a user ```www-data``` shell.
***Ro
HackerOne
CVE-2019-11043: a buffer underflow in fpm_main.c can lead to RCE in php-fpm
hackerone·2020-11-09·CVSS 8.7
CVE-2019-11043 [HIGH] CVE-2019-11043: a buffer underflow in fpm_main.c can lead to RCE in php-fpm
CVE-2019-11043: a buffer underflow in fpm_main.c can lead to RCE in php-fpm
The vulnerability exists in php-fpm because of missing bounds check in fpm_main.c. If the FastCGI variable `PATH_INFO` is empty, the underflow happens when the code tries to calculate the value of the `path_info` variable. An invalid pointer in `path_info` leads to a single byte out-of-bounds write, which can be leveraged to code execution.
The php-fpm allows anyone who can connect to its' port to execute code, so an RCE in php-fpm is not interesting by itself. However, this particular issue can be exploited even by a user who has access to the HTTP server (which is Nginx typically). In certain Nginx configurations, it is possible to make it send empty `PATH_INFO` value by breaking regexp in `fastcgi_split_pathin
HackerOne
Docker image with FPM is vulnerable to CVE-2019-11043
hackerone·2020-03-14·CVSS 8.7
CVE-2019-11043 [HIGH] Docker image with FPM is vulnerable to CVE-2019-11043
Docker image with FPM is vulnerable to CVE-2019-11043
The CVE-2019-11043 vulnerability can be exploited in the latest nextcloud:fpm image.
This is due to the specific nginx configuration recommended for nextcloud:
https://github.com/nextcloud/docker#base-version---fpm
https://github.com/nextcloud/documentation/blob/master/admin_manual/installation/nginx.rst
https://github.com/nextcloud/docker/blob/master/.examples/docker-compose/with-nginx-proxy/mariadb/fpm/web/nginx.conf
Here's the exploit: https://github.com/neex/phuip-fpizdam
Sample exploit run:
# ./phuip-fpizdam http://localhost:8080/ocs/v2.php
2019/10/22 19:36:29 Base status code is 200
2019/10/22 19:36:30 Status code 502 for qsl=1765, adding as a candidate
2019/10/22 19:36:31 The target is probably vulnerable. Possible QSLs: [175
Bugzilla
CVE-2019-11043 php: underflow in env_path_info in fpm_main.c [fedora-all]
bugzilla·2019-10-28·CVSS 8.7
CVE-2019-11043 [HIGH] CVE-2019-11043 php: underflow in env_path_info in fpm_main.c [fedora-all]
CVE-2019-11043 php: underflow in env_path_info in fpm_main.c [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of
Bugzilla
CVE-2019-11043 php: underflow in env_path_info in fpm_main.c
bugzilla·2019-10-28·CVSS 8.7
CVE-2019-11043 [HIGH] CVE-2019-11043 php: underflow in env_path_info in fpm_main.c
CVE-2019-11043 php: underflow in env_path_info in fpm_main.c
In PHP versions 7.1.x below 7.1.33, 7.2.x below 7.2.24 and 7.3.x below 7.3.11 in certain configurations of FPM setup it is possible to cause FPM module to write past allocated buffers into the space reserved for FCGI protocol data, thus opening the possibility of remote code execution.
Upstream bug:
https://bugs.php.net/bug.php?id=78599
Upstream commit:
http://git.php.net/?p=php-src.git;a=commitdiff;h=ab061f95ca966731b1c84cf5b7b20155c0a1c06a
Discussion:
Created php tracking bugs for this issue:
Affects: fedora-all [bug 1766379]
---
Notice: this issue only affects NGINX + PHP users.
Affected nginx configuration can be fixed, some details in upstream (php) bug 78599 report
---
There's an issue when running php-fpm on n
http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00011.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-11/msg00014.htmlhttp://packetstormsecurity.com/files/156642/PHP-FPM-7.x-Remote-Code-Execution.htmlhttp://seclists.org/fulldisclosure/2020/Jan/40https://access.redhat.com/errata/RHSA-2019:3286https://access.redhat.com/errata/RHSA-2019:3287https://access.redhat.com/errata/RHSA-2019:3299https://access.redhat.com/errata/RHSA-2019:3300https://access.redhat.com/errata/RHSA-2019:3724https://access.redhat.com/errata/RHSA-2019:3735https://access.redhat.com/errata/RHSA-2019:3736https://access.redhat.com/errata/RHSA-2020:0322https://bugs.php.net/bug.php?id=78599https://github.com/neex/phuip-fpizdamhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3W23TP6X4H7LB645FYZLUPNIRD5W3EPU/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FSNBUSPKMLUHHOADROKNG5GDWDCRHT5M/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/T62LF4ZWVV7OMMIZFO6IFO5QLZKK7YRD/https://seclists.org/bugtraq/2020/Jan/44https://security.netapp.com/advisory/ntap-20191031-0003/https://support.apple.com/kb/HT210919https://support.f5.com/csp/article/K75408500?utm_source=f5support&%3Butm_medium=RSShttps://usn.ubuntu.com/4166-1/https://usn.ubuntu.com/4166-2/https://www.debian.org/security/2019/dsa-4552https://www.debian.org/security/2019/dsa-4553https://www.synology.com/security/advisory/Synology_SA_19_36https://www.tenable.com/security/tns-2021-14http://lists.opensuse.org/opensuse-security-announce/2019-11/msg00011.htmlhttp://lists.opensuse.org/opensuse-security-announce/2019-11/msg00014.htmlhttp://packetstormsecurity.com/files/156642/PHP-FPM-7.x-Remote-Code-Execution.htmlhttp://seclists.org/fulldisclosure/2020/Jan/40https://access.redhat.com/errata/RHSA-2019:3286https://access.redhat.com/errata/RHSA-2019:3287https://access.redhat.com/errata/RHSA-2019:3299https://access.redhat.com/errata/RHSA-2019:3300https://access.redhat.com/errata/RHSA-2019:3724https://access.redhat.com/errata/RHSA-2019:3735https://access.redhat.com/errata/RHSA-2019:3736https://access.redhat.com/errata/RHSA-2020:0322https://bugs.php.net/bug.php?id=78599https://github.com/neex/phuip-fpizdamhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/3W23TP6X4H7LB645FYZLUPNIRD5W3EPU/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/FSNBUSPKMLUHHOADROKNG5GDWDCRHT5M/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/T62LF4ZWVV7OMMIZFO6IFO5QLZKK7YRD/https://seclists.org/bugtraq/2020/Jan/44https://security.netapp.com/advisory/ntap-20191031-0003/https://support.apple.com/kb/HT210919https://support.f5.com/csp/article/K75408500?utm_source=f5support&%3Butm_medium=RSShttps://usn.ubuntu.com/4166-1/https://usn.ubuntu.com/4166-2/https://www.debian.org/security/2019/dsa-4552https://www.debian.org/security/2019/dsa-4553https://www.synology.com/security/advisory/Synology_SA_19_36https://www.tenable.com/security/tns-2021-14https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-11043
2019-10-28
Published
2022-03-25
Added to CISA KEV
Exploited in the wild