
Hands-on lab reproducing CVE-2019-11043 PHP-FPM RCE behind nginx, demonstrating reverse-tunnel persistence, memory forensics, and network traffic analysis.
In October 2019, Debian Security Advisory researchers Emil Lerner and Andrew Danau published a notice warning the Debian community about a critical vulnerability in PHP-FPM. Due to insufficient validation in PHP-FPM’s path handling code, attackers could manipulate specially crafted requests to achieve remote arbitrary code execution under certain NGINX + PHP-FPM configurations.
This lab demonstrates the exploitation of:
A vulnerability affecting PHP-FPM running behind NGINX that, when triggered, can allow attackers to execute arbitrary code and establish persistence through reverse tunneling.
The project recreates a vulnerable environment, executes the exploit chain, and evaluates how adversaries achieve persistence through tunneling techniques in real-world scenarios.
This attack chain aligns directly with several high-impact MITRE ATT&CK techniques:
| MITRE ID | Technique Name |
|---|---|
| T1071 | Application Layer Tunneling |
| T1572 | Protocol Tunneling |
| T1090 | Proxy / Reverse Proxy |
| T1505 | Server-Side Components (PHP-FPM) |
| T1574 | Hijacking Execution Flow |
Reverse tunneling for persistence is a high-frequency TTP (Tactic, Technique, Procedure) used across APT groups, botnets, and ransomware operators. PHP-FPM remains widely deployed in production environments, and the misconfigurations exploited by CVE-2019-11043 are still observed in the wild.
These are not theoretical abstractions — they mirror the exact behaviors documented in active exploitation campaigns involving nation-state actors and ransomware groups.
Even though CVE-2019-11043 is several years old, the vulnerability continues to hold relevance due to the following modern security realities:
Legacy PHP applications are still everywhere. Many organizations continue to run outdated PHP 5.x/7.x stacks because of long-term web application dependencies, technical debt, or fear of breaking production systems. These environments often remain unpatched and vulnerable.
NGINX + PHP-FPM is one of the most common hosting architectures globally. This makes vulnerabilities in PHP-FPM extremely attractive to attackers who look for large, long-lasting exploitation surfaces.
Reverse tunneling is a core persistence technique across modern threats. Groups like Lazarus, APT29, FIN11, and numerous ransomware operators use reverse SSH tunnels, WebSocket tunnels, and even PHP-based reverse shells to maintain long-term access without relying on exposed inbound ports.
Misconfigurations remain the #1 cause of breaches. Even when patches exist, misconfigured NGINX “location” blocks and poorly validated PATH_INFO variables continue to expose environments to exploitation.
Exploit automation kits still target this CVE. Tools such as automated scanners, botnets, and IoT malware routinely probe for vulnerable PHP-FPM setups because the exploit results in reliable code execution.
Cloud environments are expanding the attack surface. Poorly secured containers, shared hosting setups, and outdated Docker base images often contain unpatched PHP-FPM versions, leading to rapid lateral movement inside cloud networks.
Attackers love "low hanging fruit." A vulnerability that enables remote code execution + tunnel-based persistence with minimal skill required will always remain a high-value target.
In today's threat landscape, where persistent access, stealthy tunneling, and supply-chain weaknesses dominate cybersecurity headlines, understanding and demonstrating how CVE-2019-11043 is exploited provides critical insight into modern attack patterns and defensive gaps.
The objective of this lab was to simulate a real‑world exploitation of CVE‑2019‑11043, a critical remote code execution vulnerability affecting PHP‑FPM behind nginx using certain configurations. The goal was to analyze the vulnerability, reproduce the exploit in a controlled virtual environment, and demonstrate the risks associated with misconfigured web infrastructure.
Two virtual machines were used: both with a username of username and password of password.
| Role | Machine | IP Address | Purpose |
|---|---|---|---|
| Target / Victim | Ubuntu Server | 192.168.56.102 | Vulnerable PHP-FPM server running CVE-2019-11043 |
| Attacker | Ubuntu Server | 192.168.56.103 | Executes exploit, reverse shell, and persistence |
Update apt
sudo apt update && sudo apt -y upgrade
Making the container for the vulnerability exploit.
sudo apt install -y docker.io docker-compose git
git clone https://github.com/vulhub/vulhub.git
cd vulhub/php/CVE-2019-11043
sudo docker-compose up -d
Update Apt, and install basic php and python and more packages
sudo apt update
sudo apt install nmap curl wget git python3 python3-pip \
netcat-traditional net-tools build-essential \
php ruby ruby-full
pip3 install requests
sudo apt install golang-go
Downloads a tool to exploit the CVE in question and moves the terminal to build the exploit.
git clone https://github.com/neex/phuip-fpizdam.git
cd phuip-fpizdam
go build
From here setup is complete, for example of what you can do first,