Apache HTTP Server
cpe:2.3:a:apache:http_server:*:*:*:*:*:*:*
- >= 2.4.17, <= 2.4.38
This vulnerability is being actively exploited in the wild.
A privilege escalation vulnerability has been identified in Apache HTTP Server versions 2.4.17 prior to 2.4.39. This issue occurs in the event, worker, or prefork Multi-Processing Modules (MPMs). The vulnerability allows code running in less-privileged child processes or threads, including those executing CGI scripts or using an in-process scripting interpreter, to execute arbitrary code with the privileges of the parent process, typically root. The exploitation is achieved by manipulating the scoreboard, which can lead to unauthorized access or modifications. Non-Unix systems are not affected.
Exploitation of this vulnerability could result in unauthorized execution of code with elevated privileges, potentially leading to a full system compromise.
The vulnerability can be reproduced by uploading a malicious CGI script to a server running an affected version of Apache HTTP Server with the event, worker, or prefork MPMs enabled. Once the script is executed, it can manipulate the scoreboard to escalate privileges and execute arbitrary code as the root user.
Users are advised to upgrade to Apache HTTP Server version 2.4.39 or later. Red Hat JBoss Core Services Apache HTTP Server 2.4.29 SP2 also includes this fix.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.