New RCE-flaw in Exim impacts almost 60% of email servers worldwide

New RCE-flaw in Exim impacts almost 60% of email servers worldwide

Yesterday we have publish a security bulletin SB2019060505 describing remote code execution vulnerability in Exim MTA. According to the recent survey, Exim is used by 57% (507,389) of all mail servers worldwide.

The flaw affects Exim installations running versions 4.87 to 4.91 and allows local and remote attackers to execute arbitrary commands with execv() call. The major concern in here is that the code will be executed with root privileges.

The vulnerability can be exploited instantly by a local attacker with the access (even having low level account) to an email server. Remote exploitation of this bug requires an attacker to maintain a connection to the vulnerable server for 7 days (by transmitting one byte every few minutes).

It is recommended to install the latest version Exim 4.92 ASAP.

Back to the list

Latest Posts

12,000 API keys and passwords found in DeepSeek's training data

12,000 API keys and passwords found in DeepSeek's training data

In total, nearly 1,500 unique MailChimp keys were found hardcoded into HTML and JavaScript on front-end webpages.
3 March 2025
Trump administration to halt offensive cyber ops against Russia

Trump administration to halt offensive cyber ops against Russia

Defense Secretary Pete Hegseth has directed Cyber Command to halt any operations aimed at countering Russian cyber activities.
3 March 2025
Serbian activist's phone targeted with Cellebrite zero-day exploit

Serbian activist's phone targeted with Cellebrite zero-day exploit

The exploit is based on a vulnerability in Android’s USB drivers and was initially discovered in 2024.
3 March 2025