CISA Known Exploited Vulnerability

CVE-2019-11043 Ransomware

PHP · FastCGI Process Manager (FPM)

PHP FastCGI Process Manager (FPM) Buffer Overflow Vulnerability

Date added
BOD 22-01 due date
CWE CWE-120
Ransomware Known

CISA description

In some versions of PHP in certain configurations of FPM setup, it is possible to cause FPM module to write past allocated buffers allowing the possibility of remote code execution.

Required action

Apply updates per vendor instructions.