Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2019-0211

93
FAUCET Score

CVE-2019-0211 is a critical local privilege escalation vulnerability affecting Apache HTTP Server versions 2.4.17 to 2.4.38 on Unix-like systems using MPM event, worker, or prefork. It allows less-privileged child processes to execute arbitrary code with root privileges by manipulating the scoreboard. With a CVSS score of 7.8 (HIGH), this vulnerability is easily exploitable locally with low complexity, leading to complete compromise of confidentiality, integrity, and availability. This CVE is actively exploited in the wild, listed in the KEV catalog, and public exploit code (EDB-46676) is available, garnering significant community discussion and media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
>= 2.4.17, <= 2.4.38CPE matchmatch criteria
cpe:2.3:a:apache:http_server:*:*:*:*:*:*:*:*
28CPE matchmatch criteria
cpe:2.3:o:fedoraproject:fedora:28:*:*:*:*:*:*:*
29CPE matchmatch criteria
cpe:2.3:o:fedoraproject:fedora:29:*:*:*:*:*:*:*
30CPE matchmatch criteria
cpe:2.3:o:fedoraproject:fedora:30:*:*:*:*:*:*:*
14.04CPE matchmatch criteria
cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:esm:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.8HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
65.00%
Probability of exploitation in next 30 days
EPSS Percentile
99.2%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
Added to KEV · Nov 3, 2021
ExploitDB: EDB-46676 · Apr 8, 2019
This CVE's current EPSS score of 0.6501 is in the 100th percentile among its peer group of 16,994 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (18)

apachepatch availablevia llm_extracted
Fixed in: 2.4
oraclepatch availablevia nvd_reference
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services Apache HTTP Server 2.4.29 SP2Fixed in: httpd
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 6Fixed in: jbcs-httpd24-httpd-0:2.4.29-40.jbcs.el6
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 6Fixed in: jbcs-httpd24-openssl-1:1.0.2n-15.jbcs.el6
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 7Fixed in: jbcs-httpd24-httpd-0:2.4.29-40.jbcs.el7
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services on RHEL 7Fixed in: jbcs-httpd24-openssl-1:1.0.2n-15.jbcs.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: httpd:2.4-8000020190405071959.55190bc5
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 6Fixed in: httpd24-httpd-0:2.4.34-7.el6.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7Fixed in: httpd24-httpd-0:2.4.34-7.el7.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7Fixed in: httpd24-mod_auth_mellon-0:0.13.1-2.el7.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7.4 EUSFixed in: httpd24-httpd-0:2.4.34-7.el7.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7.4 EUSFixed in: httpd24-mod_auth_mellon-0:0.13.1-2.el7.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUSFixed in: httpd24-httpd-0:2.4.34-7.el7.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7.5 EUSFixed in: httpd24-mod_auth_mellon-0:0.13.1-2.el7.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUSFixed in: httpd24-httpd-0:2.4.34-7.el7.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Software Collections for Red Hat Enterprise Linux 7.6 EUSFixed in: httpd24-mod_auth_mellon-0:0.13.1-2.el7.1
View patch
redhatpatch availablevia redhat_api
Product: JBoss Core Services Apache HTTP Server 2.4.29 SP2
View patch

Vendor Advisories (4)

apachellm-apache-f398f8ed28802aa3LOW

Apache HTTP Server 2.4 vulnerabilities - The Apache HTTP Server Project

Mar 2, 2026
apachellm-apache-a7a91ec4c0e9421dHIGH

Apache HTTP Server 2.4 vulnerabilities - The Apache HTTP Server Project

Dec 10, 2025
redhatCVE-2019-0211Important

httpd: privilege escalation from modules scripts

Apr 1, 2019
apachellm-apache-684e4d0003611bd4LOW

Apache HTTP Server 2.4 vulnerabilities - The Apache HTTP Server Project

References

cisa.gov / known-exploited-vulnerabilities-catalog
US Government Resource
lists.opensuse.org / opensuse-security-announce/2019-04/msg00051.html
Broken LinkMailing ListRelease NotesThird Party Advisory
lists.opensuse.org / opensuse-security-announce/2019-04/msg00061.html
Broken LinkMailing ListRelease NotesThird Party Advisory
lists.opensuse.org / opensuse-security-announce/2019-04/msg00084.html
Broken LinkThird Party Advisory
packetstormsecurity.com / files/152386/Apache-2.4.38-Root-Privilege-Escalation.html
Third Party AdvisoryVDB Entry
packetstormsecurity.com / files/152415/Slackware-Security-Advisory-httpd-Updates.html
ExploitThird Party AdvisoryVDB Entry
packetstormsecurity.com / files/152441/CARPE-DIEM-Apache-2.4.x-Local-Privilege-Escalation.html
ExploitThird Party AdvisoryVDB Entry
access.redhat.com / errata/RHBA-2019:0959
Third Party Advisory
access.redhat.com / errata/RHSA-2019:0746
Third Party Advisory
access.redhat.com / errata/RHSA-2019:0980
Third Party Advisory
access.redhat.com / errata/RHSA-2019:1296
Third Party Advisory
access.redhat.com / errata/RHSA-2019:1297
Third Party Advisory
access.redhat.com / errata/RHSA-2019:1543
Third Party Advisory
httpd.apache.org / security/vulnerabilities_24.html
Vendor Advisory
lists.apache.org / thread.html/56c2e7cc9deb1c12a843d0dc251ea7fd3e7e80293cde02fcd65286ba%40%3Ccvs.httpd.apache.org%3E
Mailing List
lists.apache.org / thread.html/84a3714f0878781f6ed84473d1a503d2cc382277e100450209231830%40%3Ccvs.httpd.apache.org%3E
Mailing List
lists.apache.org / thread.html/890507b85c30adf133216b299cc35cd8cd0346a885acfc671c04694e%40%3Cdev.community.apache.org%3E
Mailing List
lists.apache.org / thread.html/b1613d44ec364c87bb7ee8c5939949f9b061c05c06e0e90098ebf7aa%40%3Cusers.httpd.apache.org%3E
Mailing List
lists.apache.org / thread.html/b2bdb308dc015e771ba79c0586b2de6fb50caa98b109833f5d4daf28%40%3Cdev.community.apache.org%3E
Mailing List
lists.apache.org / thread.html/de881a130bc9cb2f3a9ff220784520556884fb8ea80e69400a45509e%40%3Cdev.community.apache.org%3E
Mailing List
lists.apache.org / thread.html/fd110f4ace2d8364c7d9190e1993cde92f79e4eb85576ed9285686ac%40%3Ccvs.httpd.apache.org%3E
Mailing List
lists.apache.org / thread.html/r03ee478b3dda3e381fd6189366fa7af97c980d2f602846eef935277d%40%3Ccvs.httpd.apache.org%3E
Mailing List
lists.apache.org / thread.html/r06f0d87ebb6d59ed8379633f36f72f5b1f79cadfda72ede0830b42cf%40%3Ccvs.httpd.apache.org%3E
Mailing List
lists.apache.org / thread.html/r6d03e45b81eab03580cf7f8bb51cb3e9a1b10a2cc0c6a2d3cc92ed0c%40%3Cannounce.apache.org%3E
Mailing List
lists.apache.org / thread.html/r76142b8c5119df2178be7c2dba88fde552eedeec37ea993dfce68d1d%40%3Ccvs.httpd.apache.org%3E
Mailing List
lists.apache.org / thread.html/r9f93cf6dde308d42a9c807784e8102600d0397f5f834890708bf6920%40%3Ccvs.httpd.apache.org%3E
Mailing ListPatch
lists.apache.org / thread.html/rc998b18880df98bafaade071346690c2bc1444adaa1a1ea464b93f0a%40%3Ccvs.httpd.apache.org%3E
Mailing List
lists.apache.org / thread.html/rd18c3c43602e66f9cdcf09f1de233804975b9572b0456cc582390b6f%40%3Ccvs.httpd.apache.org%3E
Mailing List
lists.apache.org / thread.html/rd2fb621142e7fa187cfe12d7137bf66e7234abcbbcd800074c84a538%40%3Ccvs.httpd.apache.org%3E
Mailing List
lists.apache.org / thread.html/re3d27b6250aa8548b8845d314bb8a350b3df326cacbbfdfe4d455234%40%3Ccvs.httpd.apache.org%3E
Mailing List
lists.apache.org / thread.html/re473305a65b4db888e3556e4dae10c2a04ee89dcff2e26ecdbd860a9%40%3Ccvs.httpd.apache.org%3E
Mailing List
lists.apache.org / thread.html/rf6449464fd8b7437704c55f88361b66f12d5b5f90bcce66af4be4ba9%40%3Ccvs.httpd.apache.org%3E
Mailing List
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/ALIR5S3O7NRHEGFMIDMUSYQIZOE4TJJN
Release Notes
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/EZRMTEIGZKYFNGIDOTXN3GNEJTLVCYU7
Release Notes
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/WETXNQWNQLWHV6XNW6YTO5UGDTIWAQGT
Release Notes
seclists.org / bugtraq/2019/Apr/16
Mailing ListPatchThird Party Advisory
seclists.org / bugtraq/2019/Apr/5
Mailing ListThird Party Advisory
security.gentoo.org / glsa/201904-20
Third Party Advisory
security.netapp.com / advisory/ntap-20190423-0001
Third Party Advisory
support.f5.com / csp/article/K32957101
Third Party Advisory
support.hpe.com / hpsc/doc/public/display
Third Party Advisory
usn.ubuntu.com / 3937-1
Third Party Advisory
debian.org / security/2019/dsa-4422
Mailing ListThird Party Advisory
exploit-db.com / exploits/46676
ExploitThird Party AdvisoryVDB Entry
oracle.com / security-alerts/cpuapr2020.html
PatchThird Party Advisory
oracle.com / technetwork/security-advisory/cpujul2019-5072835.html
PatchThird Party Advisory
oracle.com / technetwork/security-advisory/cpuoct2019-5072832.html
PatchThird Party Advisory
synology.com / security/advisory/Synology_SA_19_14
Third Party Advisory
apache.org / dist/httpd/CHANGES_2.4.39
Broken LinkVendor Advisory
openwall.com / lists/oss-security/2019/04/02/3
Mailing ListThird Party Advisory
openwall.com / lists/oss-security/2019/07/26/7
Mailing List
securityfocus.com / bid/107666
Broken LinkThird Party AdvisoryVDB Entry