CVE-2019-0211

HIGH KEV RANSOMWARE

Apache HTTP Server < 2.4.38 - Use After Free

Title source: rule

Description

In Apache HTTP Server 2.4 releases 2.4.17 to 2.4.38, with MPM event, worker or prefork, code executing in less-privileged child processes or threads (including scripts executed by an in-process scripting interpreter) could execute arbitrary code with the privileges of the parent process (usually root) by manipulating the scoreboard. Non-Unix systems are not affected.

Exploits (4)

exploitdb WORKING POC
by cfreal · phplocallinux
https://www.exploit-db.com/exploits/46676
nomisec WORKING POC 11 stars
by ozkanbilge · local
https://github.com/ozkanbilge/Apache-Exploit-2019
github WORKING POC 1 stars
by vaishakhcv · perlpoc
https://github.com/vaishakhcv/CVE-exploits/tree/master/CVE-2019-0211
github WORKING POC
by winterwolf32 · perlpoc
https://github.com/winterwolf32/CVE_Exploits-/tree/master/CVE-2019-0211

References (52)

... and 32 more

Scores

CVSS v3 7.8
EPSS 0.9091
EPSS Percentile 99.6%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CISA KEV 2021-11-03
VulnCheck KEV 2021-11-03
InTheWild.io 2021-07-23
ENISA EUVD EUVD-2019-1002
Ransomware Use Confirmed
CWE
CWE-416
Status published
Products (50)
apache/http_server 2.4.17 - 2.4.38
canonical/ubuntu_linux 14.04
canonical/ubuntu_linux 16.04
canonical/ubuntu_linux 18.04
canonical/ubuntu_linux 18.10
debian/debian_linux 9.0
fedoraproject/fedora 28
fedoraproject/fedora 29
fedoraproject/fedora 30
netapp/oncommand_unified_manager
... and 40 more
Published Apr 08, 2019
KEV Added Nov 03, 2021
Tracked Since Feb 18, 2026