Description
In Apache HTTP Server 2.4 releases 2.4.17 to 2.4.38, with MPM event, worker or prefork, code executing in less-privileged child processes or threads (including scripts executed by an in-process scripting interpreter) could execute arbitrary code with the privileges of the parent process (usually root) by manipulating the scoreboard. Non-Unix systems are not affected.
In plain language
AI Act nowCVE-2019-0211 is a serious Apache HTTP Server flaw where malicious code from a low-privileged script/process can make Apache run arbitrary code as the main (often root) process—if your small business runs Apache 2.4 in the affected range on Unix, you should act now.
CVE-2019-0211 is a local code execution flaw in Apache HTTP Server 2.4 (2.4.17 through 2.4.38) on Unix with MPM event, worker, or prefork, where attackers who can execute code in a child process/thread can manipulate Apache's scoreboard to run arbitrary code with the privileges of the main Apache process.
CVSS Vector Breakdown
AV:LAttack VectorAC:LAttack ComplexityPR:LPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Required action: Apply updates per vendor instructions.
Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.
View exploit detailsAttack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
2 techniquesReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2019-0211 and every CVE in our database. Create a free account — no credit card required.
Create Free Account