CVE-2019-0211
CISA 기관 조치 기한: 2022-05-03
Apache HTTP Server
Qualys 위협 인텔 · 심각도 3/5 · QID 377378 · Local
공개 익스플로잇
실제 공격 관측
쉬운 악용
서비스 거부
악성코드 연계
권한상승
원격코드실행
랜섬웨어 연계
CISA KEV
Apache HTTP Server, with MPM event, worker or prefork, code executing in less-privileged child processes or threads (including scripts executed by an in-process scripting interpreter) could execute code with the privileges of the parent process (usually root) by manipulating the scoreboard.
KEV 필수 조치: Apply updates per vendor instructions.
공개 익스플로잇 / PoC
- GitHub 공개 PoC 1건 — 대표 레포 ↗
- Exploit-DB: EDB-46676 ↗