CVE-2019-0211
KEVHIGH 7.8EPSS 65.0%
In Apache HTTP Server 2.4 releases 2.4.17 to 2.4.38, with MPM event, worker or prefork, code executing in less-privileged child processes or threads (including scripts executed by an in-process scripting interpreter) could execute arbitrary code with the privileges of the parent process (usually root) by manipulating the scoreboard. Non-Unix systems are not affected.
- CVSS v3.1
- 7.8 HIGH
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H - CVSS v3.1
- 7.8 HIGH
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H - CVSS v2.0
- 7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C - EPSS
- 65.00% chance of exploitation in the next 30 days, 99th percentile
- CISA KEV
- added 2021-11-03
- Published
- 2019-04-08
- Updated
- 2025-10-21
Proof-of-concept exploits (5)
- http://packetstormsecurity.com/files/152415/Slackware-Security-Advisory-httpd-Updates.html
- http://packetstormsecurity.com/files/152441/CARPE-DIEM-Apache-2.4.x-Local-Privilege-Escal…
- 0xbigshaq/php7-internals262★ · 2020-07-05
- ozkanbilge/Apache-Exploit-201911★ · 2019-05-12
- Jeanback1/CVE-2019-0211-exploit