CVE-2019-0211 is a critical local privilege escalation vulnerability affecting Apache HTTP Server versions 2.4.17 to 2.4.38 on Unix-like systems using MPM event, worker, or prefork. It allows less-privileged child processes to execute arbitrary code with root privileges by manipulating the scoreboard. With a CVSS score of 7.8 (HIGH), this vulnerability is easily exploitable locally with low complexity, leading to complete compromise of confidentiality, integrity, and availability. This CVE is actively exploited in the wild, listed in the KEV catalog, and public exploit code (EDB-46676) is available, garnering significant community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.4.17, <= 2.4.38CPE matchmatch criteria | cpe:2.3:a:apache:http_server:*:*:*:*:*:*:*:* | ||
28CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:28:*:*:*:*:*:*:* | ||
29CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:29:*:*:*:*:*:*:* | ||
30CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:30:*:*:*:*:*:*:* | ||
14.04CPE matchmatch criteria | cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:esm:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Apache HTTP Server 2.4 vulnerabilities - The Apache HTTP Server Project
Mar 2, 2026Apache HTTP Server 2.4 vulnerabilities - The Apache HTTP Server Project
Dec 10, 2025httpd: privilege escalation from modules scripts
Apr 1, 2019Apache HTTP Server 2.4 vulnerabilities - The Apache HTTP Server Project