
The most widely used Web server , Apache HTTP, appears to have patched a serious vulnerability that allows hackers or malware to gain unlimited control over a machine.
The flaw, called CVE-2019-0211, is a local privilege escalation bug, meaning it allows a person or software that already has limited access to a server to gain root privileges. From there, an attacker could do almost anything on a system. According to Charles Fol, a researcher who discovered the flaw, the vulnerability makes it possible for unauthorized attackers to overwrite sensitive parts of a server's memory. A malicious script could exploit the vulnerability to gain root access.
The vulnerability poses the greatest risk to Web-hosting facilities that offer shared hosting, in which a machine serves content for more than one website. Typically, these servers prevent a website administrator from accessing other websites or accessing sensitive settings on the machine itself.
“If one of the users successfully exploits the vulnerability, they will have full access to the server, as well as the web hoster,” Fol said. “This means reading/writing/deleting any file/database of other users.”
The other possible scenario for exploitation is if an attacker using a different attack gains only limited privileges on a server running Apache. If the server is vulnerable to CVE-2019-0211, the attacker could exploit the flaw to elevate those limited privileges to root.
The vulnerability only affects Apache versions 2.4.17 through 2.4.38 when running on UNIX-like systems. According to security firm Rapid7, about 2 million different systems were vulnerable to CVE-2019-0211, although most have likely been updated since the bug was published.

