CVE-2021-21703

PHP-FPM memory access in root process leading to privilege escalation

In PHP versions 7.3.x up to and including 7.3.31, 7.4.x below 7.4.25 and 8.0.x below 8.0.12, when running PHP FPM SAPI with main FPM daemon process running as root and child worker processes running as lower-privileged users, it is possible for the child processes to access memory shared with the main process and write to it, modifying it in a way that would cause the root process to conduct invalid memory reads and writes, which can be used to escalate privileges from local unprivileged user to the root user.


We have discovered 414,579 live websites that are affected by CVE-2021-21703.

Run a Free Instant Scan




Affected Software

Product  PHP
Category Programming Languages
Vulnerable Domains414,579 live websites (5.43% of PHP install base)
Vulnerable Versions
  • from 7.3 through 7.3.31
  • from 7.4 through 7.4.25
  • from 8 through 8.0.12
Vulnerable Versions Count67 versions ( 13% of all versions)


Common Weakness Enumeration

CWE-787 Out-of-bounds Write



Details

  • Published - Oct 25, 2021
  • Updated - Sep 17, 2024

Credits

  • Reported by Charles Fol

Website Distribution by Country

Number of websites using CVE-2021-21703
United States135,982 websites



France138,396 websites
Russia20,897 websites
Germany13,087 websites
Japan9,369 websites
China8,592 websites
Brazil7,259 websites
Spain6,656 websites
Poland6,538 websites
Italy6,296 websites

Website Distribution by TLD

Number of websites using CVE-2021-21703
.com194,945 websites
.fr57,620 websites
.org21,003 websites
.ru16,921 websites
.net12,563 websites
.de7,977 websites
.be7,045 websites
.pl6,262 websites
.it6,187 websites
.com.br6,156 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2021-21703

Top websites that are affected by CVE-2021-21703. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
*****.pl Poland*,***
****.org GB*,***
**********.org United States*,***
******.com France*,***
**********.com France*,***
*******.pro Russia*,***
*********.ua Ukraine*,***
******.at Austria*,***
******.com France*,***
*********.com United States*,***
See full domain list

FAQ

CVE-2021-21703 is Out-of-bounds Write in PHP
A total of 414,579 websites have been identified as vulnerable to CVE-2021-21703, based on global website indexing conducted by WebTechSurvey.
The PHP is affected by the CVE-2021-21703 vulnerability.
PHP versions up to 8.0.12 are vulnerable to CVE-2021-21703.
CVE-2021-21703 is resolved in version 8.0.12 of PHP.

References