PatchSiren cyber security CVE debrief
CVE-2019-11043 PHP CVE debrief
CVE-2019-11043 is listed by CISA in the Known Exploited Vulnerabilities catalog as a PHP FastCGI Process Manager (FPM) buffer overflow vulnerability. The supplied record marks it as known exploited and notes known ransomware campaign use. Organizations running PHP FPM should treat this as a high-priority remediation item and follow vendor guidance to apply updates and verify exposure has been removed.
- Vendor
- PHP
- Product
- FastCGI Process Manager (FPM)
- CVSS
- CRITICAL 9.8
- CISA KEV
- Listed
- Original CVE published
- 2022-03-25
- Original CVE updated
- 2022-03-25
- Advisory published
- 2022-03-25
- Advisory updated
- 2022-03-25
Who should care
Security teams, platform owners, and incident responders responsible for PHP FPM deployments, especially internet-facing web servers and applications that depend on PHP.
Technical summary
The supplied corpus identifies the issue as a buffer overflow in PHP FastCGI Process Manager (FPM). No affected-version list, scoring, or exploit mechanics are included in the provided materials, so the safest defensive reading is that PHP FPM instances should be inventoried, patched according to vendor instructions, and validated after remediation.
Defensive priority
High. CISA has placed the vulnerability in the KEV catalog, recorded known ransomware campaign use, and set a required action to apply updates per vendor instructions. The supplied KEV metadata lists 2022-03-25 as the catalog date and 2022-04-15 as the due date.
Recommended defensive actions
- Inventory all PHP FPM deployments, including packages bundled with web stacks and application servers.
- Apply the vendor-recommended updates or mitigations referenced by the official CVE and NVD records.
- Prioritize externally reachable systems and confirm the fixed version is actually installed.
- Review logs and operational alerts for abnormal PHP FPM crashes, unexpected failures, or other signs of exploitation.
- Track the item as a high-priority remediation in vulnerability management until closure is verified.
Evidence notes
This debrief is limited to the supplied CISA KEV metadata and the official CVE/NVD/CISA links. The corpus does not include CVSS scores, affected version ranges, or exploit details, so no unsupported technical specifics are included.
Sources and references
Verified primary and authoritative sources
-
CVE-2019-11043 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2019-11043
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2019-11043 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2019-11043
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
-
CISA Known Exploited Vulnerabilities catalog
Publisher, destination, and source semantics verified
URL: https://www.cisa.gov/known-exploited-vulnerabilities-catalog
Cybersecurity and Infrastructure Security Agency - Official CISA catalog of vulnerabilities known to be exploited in the wild.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json
cisa_kev
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.