CVE-2019-0211
Apache HTTP Server Privilege Escalation Vulnerability
Description
CVE-2019-0211 is a high-severity privilege escalation vulnerability in Apache HTTP Server versions 2.4.17 through 2.4.38, affecting Unix systems with MPM event, worker, or prefork configurations. Code executing in less-privileged child processes or threads, including scripts executed by in-process scripting interpreters, could execute arbitrary code with the privileges of the parent process (usually root) by manipulating the scoreboard. CISA has added CVE-2019-0211 to its Known Exploited Vulnerabilities catalog, confirming active exploitation. With an EPSS score of 89.1% (99.5th percentile), exploitation probability is very high.
KEV Information
CVSS Score
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HOpen in CalculatorAffected Products
| Vendor | Product | Version |
|---|---|---|
| apache | http server | >= 2.4.17, <= 2.4.38 |
| fedoraproject | fedora | 28; 29; 30 |
| canonical | ubuntu linux | 14.04; 16.04; 18.04; 18.10 |
| debian | debian linux | 9.0 |
| opensuse | leap | 15.0; 42.3 |
| netapp | oncommand unified manager | - |
| redhat | jboss core services | 1.0 |
| redhat | openshift container platform | 3.11 |
| redhat | openshift container platform for power | 3.11_ppc64le |
| redhat | software collections | 1.0 |
| redhat | enterprise linux | 8.0 |
| redhat | enterprise linux eus | 8.1; 8.2; 8.4; 8.6; 8.8 |
| redhat | enterprise linux for arm 64 | 8.0_aarch64 |
| redhat | enterprise linux for arm 64 eus | 8.1_aarch64; 8.2_aarch64; 8.4_aarch64; 8.6_aarch64; 8.8_aarch64 |
| redhat | enterprise linux for ibm z systems | 8.0_s390x |
| redhat | enterprise linux for ibm z systems eus | 8.1_s390x; 8.2_s390x; 8.4_s390x; 8.6_s390x; 8.8_s390x |
| redhat | enterprise linux for power little endian | 8.0_ppc64le |
| redhat | enterprise linux for power little endian eus | 8.1_ppc64le; 8.2_ppc64le; 8.4_ppc64le; 8.6_ppc64le; 8.8_ppc64le |
| redhat | enterprise linux server aus | 8.2; 8.4; 8.6 |
| redhat | enterprise linux server tus | 8.2; 8.4; 8.6; 8.8 |
Multiple CVSS Assessments
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
References
- http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00051.html(Broken Link, Mailing List, Release Notes, Third Party Advisory)
- http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00061.html(Broken Link, Mailing List, Release Notes, Third Party Advisory)
- http://lists.opensuse.org/opensuse-security-announce/2019-04/msg00084.html(Broken Link, Third Party Advisory)
- http://packetstormsecurity.com/files/152386/Apache-2.4.38-Root-Privilege-Escalation.html(Third Party Advisory, VDB Entry)
- http://packetstormsecurity.com/files/152415/Slackware-Security-Advisory-httpd-Updates.html(Exploit, Third Party Advisory, VDB Entry)
- http://packetstormsecurity.com/files/152441/CARPE-DIEM-Apache-2.4.x-Local-Privilege-Escalation.html(Exploit, Third Party Advisory, VDB Entry)
- http://www.apache.org/dist/httpd/CHANGES_2.4.39(Broken Link, Vendor Advisory)
- http://www.openwall.com/lists/oss-security/2019/04/02/3(Mailing List, Third Party Advisory)
- http://www.openwall.com/lists/oss-security/2019/07/26/7(Mailing List)
- http://www.securityfocus.com/bid/107666(Broken Link, Third Party Advisory, VDB Entry)
- https://access.redhat.com/errata/RHBA-2019:0959(Third Party Advisory)
- https://access.redhat.com/errata/RHSA-2019:0746(Third Party Advisory)
- https://access.redhat.com/errata/RHSA-2019:0980(Third Party Advisory)
- https://access.redhat.com/errata/RHSA-2019:1296(Third Party Advisory)
- https://access.redhat.com/errata/RHSA-2019:1297(Third Party Advisory)
- https://access.redhat.com/errata/RHSA-2019:1543(Third Party Advisory)
- https://httpd.apache.org/security/vulnerabilities_24.html(Vendor Advisory)
- https://lists.apache.org/thread.html/56c2e7cc9deb1c12a843d0dc251ea7fd3e7e80293cde02fcd65286ba%40%3Ccvs.httpd.apache.org%3E(Mailing List)
- https://lists.apache.org/thread.html/84a3714f0878781f6ed84473d1a503d2cc382277e100450209231830%40%3Ccvs.httpd.apache.org%3E(Mailing List)
- https://lists.apache.org/thread.html/890507b85c30adf133216b299cc35cd8cd0346a885acfc671c04694e%40%3Cdev.community.apache.org%3E(Mailing List)
- https://lists.apache.org/thread.html/b1613d44ec364c87bb7ee8c5939949f9b061c05c06e0e90098ebf7aa%40%3Cusers.httpd.apache.org%3E(Mailing List)
- https://lists.apache.org/thread.html/b2bdb308dc015e771ba79c0586b2de6fb50caa98b109833f5d4daf28%40%3Cdev.community.apache.org%3E(Mailing List)
- https://lists.apache.org/thread.html/de881a130bc9cb2f3a9ff220784520556884fb8ea80e69400a45509e%40%3Cdev.community.apache.org%3E(Mailing List)
- https://lists.apache.org/thread.html/fd110f4ace2d8364c7d9190e1993cde92f79e4eb85576ed9285686ac%40%3Ccvs.httpd.apache.org%3E(Mailing List)
- https://lists.apache.org/thread.html/r03ee478b3dda3e381fd6189366fa7af97c980d2f602846eef935277d%40%3Ccvs.httpd.apache.org%3E(Mailing List)
- https://lists.apache.org/thread.html/r06f0d87ebb6d59ed8379633f36f72f5b1f79cadfda72ede0830b42cf%40%3Ccvs.httpd.apache.org%3E(Mailing List)
- https://lists.apache.org/thread.html/r6d03e45b81eab03580cf7f8bb51cb3e9a1b10a2cc0c6a2d3cc92ed0c%40%3Cannounce.apache.org%3E(Mailing List)
- https://lists.apache.org/thread.html/r76142b8c5119df2178be7c2dba88fde552eedeec37ea993dfce68d1d%40%3Ccvs.httpd.apache.org%3E(Mailing List)
- https://lists.apache.org/thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3E(Mailing List, Patch)
- https://lists.apache.org/thread.html/rc998b18880df98bafaade071346690c2bc1444adaa1a1ea464b93f0a%40%3Ccvs.httpd.apache.org%3E(Mailing List)
- https://lists.apache.org/thread.html/rd18c3c43602e66f9cdcf09f1de233804975b9572b0456cc582390b6f%40%3Ccvs.httpd.apache.org%3E(Mailing List)
- https://lists.apache.org/thread.html/rd2fb621142e7fa187cfe12d7137bf66e7234abcbbcd800074c84a538%40%3Ccvs.httpd.apache.org%3E(Mailing List)
- https://lists.apache.org/thread.html/re3d27b6250aa8548b8845d314bb8a350b3df326cacbbfdfe4d455234%40%3Ccvs.httpd.apache.org%3E(Mailing List)
- https://lists.apache.org/thread.html/re473305a65b4db888e3556e4dae10c2a04ee89dcff2e26ecdbd860a9%40%3Ccvs.httpd.apache.org%3E(Mailing List)
- https://lists.apache.org/thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3E(Mailing List)
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/ALIR5S3O7NRHEGFMIDMUSYQIZOE4TJJN/(Release Notes)
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EZRMTEIGZKYFNGIDOTXN3GNEJTLVCYU7/(Release Notes)
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WETXNQWNQLWHV6XNW6YTO5UGDTIWAQGT/(Release Notes)
- https://seclists.org/bugtraq/2019/Apr/16(Mailing List, Patch, Third Party Advisory)
- https://seclists.org/bugtraq/2019/Apr/5(Mailing List, Third Party Advisory)
- https://security.gentoo.org/glsa/201904-20(Third Party Advisory)
- https://security.netapp.com/advisory/ntap-20190423-0001/(Third Party Advisory)
- https://support.f5.com/csp/article/K32957101(Third Party Advisory)
- https://support.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbux03950en_us(Third Party Advisory)
- https://usn.ubuntu.com/3937-1/(Third Party Advisory)
- https://www.debian.org/security/2019/dsa-4422(Mailing List, Third Party Advisory)
- https://www.exploit-db.com/exploits/46676/(Exploit, Third Party Advisory, VDB Entry)
- https://www.oracle.com/security-alerts/cpuapr2020.html(Patch, Third Party Advisory)
- https://www.oracle.com/technetwork/security-advisory/cpujul2019-5072835.html(Patch, Third Party Advisory)
- https://www.oracle.com/technetwork/security-advisory/cpuoct2019-5072832.html(Patch, Third Party Advisory)
- https://www.synology.com/security/advisory/Synology_SA_19_14(Third Party Advisory)
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-0211(US Government Resource)
Weakness Type
CWE-416: Use After Free
In Apache HTTP Server, the use after free vulnerability exists in the scoreboard handling mechanism used by the MPM (Multi-Processing Module) event, worker, and prefork modes. Less-privileged child processes can manipulate scoreboard entries to trigger a use after free condition in the parent process, allowing arbitrary code execution with the parent's elevated privileges (typically root).
Learn more: CWE-416 — Use After Free
Impact Analysis
CVE-2019-0211 carries a CVSS 3.1 score of 7.8 (HIGH), representing a serious local privilege escalation threat. The attack requires local access and low privileges but has low complexity and needs no user interaction. Successful exploitation provides complete control over confidentiality, integrity, and availability, as the attacker escalates from a web script or low-privileged child process to root-level execution. The EPSS score of 89.1% indicates a very high probability of exploitation activity. This vulnerability is particularly dangerous in shared hosting environments where multiple users run scripts through the same Apache instance — a compromised script can escalate to root and compromise the entire server, affecting all hosted sites and services.
Exploit Maturity
CVE-2019-0211 has extensive exploit maturity with confirmed active exploitation. CISA has listed it in the Known Exploited Vulnerabilities catalog. Public exploit code is available via Packet Storm Security (CARPE-DIEM) and Exploit Database, both providing local privilege escalation exploits for Apache 2.4.x. An additional exploit is available via Slackware httpd Updates. The EPSS score of 89.1% (99.5th percentile) confirms a very high probability of exploitation. The technique known as "CARPE-DIEM" (CVE-2019-0211 Apache Root Privilege Escalation) demonstrates reliable exploitation through scoreboard manipulation.
Remediation
- Upgrade Apache HTTP Server immediately as mandated by CISA KEV: Apply updates per vendor instructions. Upgrade to Apache HTTP Server 2.4.39 or later, which addresses the scoreboard manipulation vulnerability.
- Verify that all Apache HTTP Server instances running versions 2.4.17 through 2.4.38 have been updated, including those deployed in Fedora (28, 29, 30), Ubuntu (14.04-18.10), Debian 9.0, openSUSE Leap, Red Hat Enterprise Linux 8.x, and OpenShift Container Platform 3.11.
- In shared hosting environments, implement additional isolation through containerization or separate Apache instances per tenant to limit the blast radius of potential privilege escalation.
- Monitor for suspicious scoreboard manipulation patterns and unexpected root-level process activity associated with Apache worker processes, particularly in shared hosting configurations.
- Audit all scripts and applications running within Apache's in-process interpreters (mod_php, mod_perl, mod_python) for signs of compromise that could be leveraged for privilege escalation.
Technical Details
CVE-2019-0211 is a privilege escalation vulnerability in Apache HTTP Server versions 2.4.17 through 2.4.38, affecting Unix systems using MPM event, worker, or prefork modules. The vulnerability involves a use after free condition in the scoreboard handling mechanism that child processes use to communicate status to the parent process. The CVSS vector CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H reflects local exploitation requiring low privileges with no user interaction. Malicious code executing in a less-privileged child process, such as a PHP script running under mod_php, can manipulate scoreboard entries in a way that triggers a use after free when the parent process reads the scoreboard. Since the parent process runs as root on most Unix systems, successful exploitation grants root-level code execution, completely compromising the host system.
Frequently Asked Questions
Is CVE-2019-0211 being actively exploited?
Yes. CVE-2019-0211 is listed in the CISA Known Exploited Vulnerabilities catalog, confirming active exploitation. The EPSS score of 89.1% (99.5th percentile) indicates a very high probability of exploitation, and multiple public exploits including the CARPE-DIEM technique are widely available.
What products are affected by CVE-2019-0211?
CVE-2019-0211 affects Apache HTTP Server versions 2.4.17 through 2.4.38 on Unix systems. Additionally affected are Fedora 28-30, Ubuntu 14.04-18.10, Debian 9.0, openSUSE Leap, Red Hat Enterprise Linux 8.x, Red Hat OpenShift Container Platform 3.11, NetApp OnCommand Unified Manager, and various other Linux distributions.
How do I fix CVE-2019-0211?
Upgrade Apache HTTP Server to version 2.4.39 or later. For distribution-specific packages, apply updates from your vendor (Red Hat, Ubuntu, Debian, SUSE). In shared hosting environments, implement additional isolation measures to limit the impact of potential exploitation.
How severe is CVE-2019-0211?
CVE-2019-0211 has a CVSS 3.1 score of 7.8 (HIGH) and an EPSS score of 89.1% (99.5th percentile). The vulnerability enables privilege escalation from a web script to root on Unix systems, making it especially dangerous in shared hosting environments.
Need Help With Vulnerability Management?
Our security experts can help you prioritize and remediate vulnerabilities effectively.