Vulnerability record · CVE-2019-0211 · published 8 April 2019
CVE-2019-0211: Apache HTTP Server scoreboard use-after-free local privilege escalation
Apache · Http Server
Apache HTTP Server 2.4.17 through 2.4.38 with MPM event, worker or prefork contains a use-after-free in scoreboard handling. Code running in a less-privileged child process or thread, including in-process scripting interpreters, can manipulate the scoreboard to execute arbitrary code as the parent process, typically root. Non-Unix systems are not affected.
Description
In Apache HTTP Server 2.4 releases 2.4.17 to 2.4.38, with MPM event, worker or prefork, code executing in less-privileged child processes or threads (including scripts executed by an in-process scripting interpreter) could execute arbitrary code with the privileges of the parent process (usually root) by manipulating the scoreboard. Non-Unix systems are not affected.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityIt is in CISA KEV with public exploit code and a high EPSS score, and successful exploitation yields root, though it requires an existing low-privileged execution context.
What it is
Apache HTTP Server 2.4.17 through 2.4.38 with MPM event, worker or prefork contains a use-after-free in scoreboard handling. Code running in a less-privileged child process or thread, including in-process scripting interpreters, can manipulate the scoreboard to execute arbitrary code as the parent process, typically root. Non-Unix systems are not affected.
Impact
An attacker who already has code execution in a child process gains root privileges on the host. This turns a limited web or script foothold into full system compromise.
Attack surface
The flaw is local, reached from code already executing inside an Apache child process or thread, including scripts run by an in-process interpreter. No user interaction is required, but the attacker needs a low-privileged execution context on the target, as reflected by the CVSS vector AV:L/PR:L/UI:N.
Exploitation
CVE-2019-0211 is listed in CISA KEV with a due date of 2022-05-03, and EPSS gives a 30-day probability of 0.65005 (99.2nd percentile). Multiple references are tagged Exploit, indicating public exploit code exists; KEV records no known ransomware campaign use.
What to do
- Upgrade Apache HTTP Server to 2.4.39 or later, or apply the vendor update for your distribution.
- Apply the referenced Red Hat, Debian, Ubuntu, SUSE, Oracle or NetApp advisories for packaged deployments.
- Reduce the number of untrusted scripts or modules running inside Apache child processes where feasible.
- Run Apache workers under a dedicated low-privilege account and restrict local access to the host.
- Verify the running httpd version after patching to confirm the fix is active.
Detection
- Monitor for unexpected child processes of httpd running as root or spawning shells.
- Alert on httpd processes accessing or modifying scoreboard-related shared memory in abnormal ways.
- Watch for local privilege escalation activity from web server accounts, including new root-owned processes.
- Audit installed httpd versions against the 2.4.17 to 2.4.38 affected range.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2019-0211 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "Apache HTTP Server Privilege Escalation Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 3 May 2022.
Affected products
27 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2019-0211 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2019-0211), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.