CVE-2019-11043This vulnerability is part of CISA's Known Exploited Vulnerabilities (KEV) catalog, indicating active exploitation in the wild. It has been observed in ransomware campaigns.
In some versions of PHP in certain configurations of FPM setup, it is possible to cause FPM module to write past allocated buffers allowing the possibility of remote code execution.
PHP
FastCGI Process Manager (FPM)
See vendor advisoryThis vulnerability was identified in FastCGI Process Manager (FPM) by PHP. In some versions of PHP in certain configurations of FPM setup, it is possible to cause FPM module to write past allocated buffers allowing the possibility of remote code execution.
High - Known ransomware exploitation
Complete system compromise possible
https://nvd.nist.gov/vuln/detail/CVE-2019-11043
Apply updates per vendor instructions.
Due Date: 4/15/2022