---
cve: "CVE-2019-0211"
severity: "HIGH"
cvss: 7.8
epss: "65%"
vendor: "Apache"
kev: true
exploited: true
published: "2019-04-08 22:29:00"
tags: [cve, security, high]
source: tsecurity.de CVE-Dossier
exported: "2026-09-03T00:31:37+02:00"
---

# CVE-2019-0211

> 7.8 HIGH · ⚠️ CISA KEV (1764 Tage) · 🔓 Exploited · 🧪 PoC

## Beschreibung

In Apache HTTP Server 2.4 releases 2.4.17 to 2.4.38, with MPM event, worker or prefork, code executing in less-privileged child processes or threads (including scripts executed by an in-process scripting interpreter) could execute arbitrary code with the privileges of the parent process (usually root) by manipulating the scoreboard. Non-Unix systems are not affected.

## CVSS-Vektor

```
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Lokal | good |
| AC Komplexität | Gering | bad |
| PR Privilegien | Gering | warn |
| UI Interaktion | Keine | bad |
| S Scope | Unverändert | good |
| C Vertraulichkeit | Hoch | bad |
| I Integrität | Hoch | bad |
| A Verfügbarkeit | Hoch | bad |

## Exploit-Evidenz

- [EDB-46676 — Apache 2.4.17 < 2.4.38 - 'apache2ctl graceful' 'logrotate' Local Privilege Escalation](https://www.exploit-db.com/exploits/46676)

## Referenzen

- <http://www.openwall.com/lists/oss-security/2019/04/02/3>
- <http://www.securityfocus.com/bid/107666>
- <https://seclists.org/bugtraq/2019/Apr/5>
- <https://www.synology.com/security/advisory/Synology_SA_19_14>
- <http://packetstormsecurity.com/files/152386/Apache-2.4.38-Root-Privilege-Escalation.html>
- <https://usn.ubuntu.com/3937-1/>
- <https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WETXNQWNQLWHV6XNW6YTO5UGDTIWAQGT/>
- <https://www.debian.org/security/2019/dsa-4422>
- <https://lists.apache.org/thread.html/b1613d44ec364c87bb7ee8c5939949f9b061c05c06e0e90098ebf7aa%40%3Cusers.httpd.apache.org%3E>
- <https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/EZRMTEIGZKYFNGIDOTXN3GNEJTLVCYU7/>
- <https://seclists.org/bugtraq/2019/Apr/16>
- <https://www.exploit-db.com/exploits/46676/>
- <https://httpd.apache.org/security/vulnerabilities_24.html>
- <http://packetstormsecurity.com/files/152415/Slackware-Security-Advisory-httpd-Updates.html>
- <http://packetstormsecurity.com/files/152441/CARPE-DIEM-Apache-2.4.x-Local-Privilege-Escalation.html>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2019-0211) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
