6 June 2019

New RCE-flaw in Exim impacts almost 60% of email servers worldwide


New RCE-flaw in Exim impacts almost 60% of email servers worldwide

Yesterday we have publish a security bulletin SB2019060505 describing remote code execution vulnerability in Exim MTA. According to the recent survey, Exim is used by 57% (507,389) of all mail servers worldwide.

The flaw affects Exim installations running versions 4.87 to 4.91 and allows local and remote attackers to execute arbitrary commands with execv() call. The major concern in here is that the code will be executed with root privileges.

The vulnerability can be exploited instantly by a local attacker with the access (even having low level account) to an email server. Remote exploitation of this bug requires an attacker to maintain a connection to the vulnerable server for 7 days (by transmitting one byte every few minutes).

It is recommended to install the latest version Exim 4.92 ASAP.

Back to the list

Latest Posts

China-alligned PlushDaemon APT linked to 2023 VPN supply chain attack

China-alligned PlushDaemon APT linked to 2023 VPN supply chain attack

The attackers replaced a legitimate installer with a malicious version that planted the SlowStepper backdoor on the system.
22 January 2025
New Murdoc botnet targets AVTECH cameras and Huawei routers for large-scale DDoS attacks

New Murdoc botnet targets AVTECH cameras and Huawei routers for large-scale DDoS attacks

The botnet operates through an extensive network of over 100 command-and-control servers.
22 January 2025
US President Trump grants full pardon to Silk Road founder Ross Ulbricht

US President Trump grants full pardon to Silk Road founder Ross Ulbricht

Ulbricht has spent over a decade behind bars after being sentenced to life in prison without the possibility of parole.
22 January 2025