CVE-2021-21703


PHP-FPM memory access in root process leading to privilege escalation

In PHP versions 7.3.x up to and including 7.3.31, 7.4.x below 7.4.25 and 8.0.x below 8.0.12, when running PHP FPM SAPI with main FPM daemon process running as root and child worker processes running as lower-privileged users, it is possible for the child processes to access memory shared with the main process and write to it, modifying it in a way that would cause the root process to conduct invalid memory reads and writes, which can be used to escalate privileges from local unprivileged user to the root user.



We have discovered 1,010,879 live websites that are affected by CVE-2021-21703.

Contact us to get more info




Affected Software

Product  PHP
Category Programming Languages
Vulnerable Versions
  • from 7.3 through 7.3.31
  • from 7.4 before 7.4.25
  • from 8 before 8.0.12
Total Vulnerable Versions507
Vulnerable Domains1,010,879 live websites (8.36% of PHP install base)


Common Weakness Enumeration


CWE-787 Out-of-bounds Write


Distribution by Website Rank

The diagram provides a graphic representation of the correlation between the occurrence of CVE-2021-21703 and the relative popularity of websites


Details

  • Published - Oct 18, 2021
  • Updated - Sep 29, 2022

Credits

  • Reported by Charles Fol





Countries

United States364,869 websites



France253,734 websites
Russia39,701 websites
Germany30,548 websites
GB23,266 websites
Canada22,119 websites
Brazil20,888 websites
Poland19,030 websites
Spain18,895 websites
Italy18,732 websites

TLDs

.com492,778 websites
.fr112,616 websites
.org56,876 websites
.ru32,224 websites
.net31,451 websites
.de18,856 websites
.com.br16,945 websites
.pl14,605 websites
.be14,077 websites
.it13,912 websites

Vulnerable Versions

Vulnerable versions are highlighted in red


Geographical Distribution

The distribution of websites across the globe that are exposed to CVE-2021-21703 through included software libraries and plugins.



References


Websites affected by CVE-2021-21703

Top websites that are affected by CVE-2021-21703. Please click on the "Contact us" button above to get more information.
DomainCountryRankContacts
***.*****.pl Poland*,***
*******.com Germany*,***
****.org GB*,***
***************.org United States*,***
***.ly United States*,***
**********.org United States*,***
***.**.gov United States*,***
***.**********.org United States*,***
******.com France*,***
**********.com France*,***
See full domain list