Exim 4.72 and earlier allows local users to gain privileges by leveraging the ability of the exim user account to specify an alternate configuration file with a directive that contains arbitrary commands, as demonstrated by the spool_directory directive.
CVSS Details
- CVSS 3.1 Base Score: 7.8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade exim-docUpgrade exim-monUpgrade eximUpgrade exim-sa | Dec 1, 2016 | Dec 14, 2010 |
| Debian | — | Upgrade exim4 | Jul 30, 2024 | Dec 14, 2010 |
| Exim | — | Upgrade Exim to version 4.72.0 | Dec 3, 2019 | Dec 14, 2010 |
| Freebsd | — | Upgrade exim | Dec 10, 2025 | Jan 8, 2011 |
| Gentoo Linux | — | Upgrade mail-mta/exim. | Oct 30, 2017 | Dec 14, 2010 |
| Oracle_linux | — | Upgrade exim-saUpgrade exim-monUpgrade exim | Oct 16, 2024 | Dec 14, 2010 |
| Suse | — | Upgrade eximUpgrade eximstats-htmlUpgrade eximon | Feb 17, 2015 | Dec 14, 2010 |
| Ubuntu | — | Upgrade exim4-daemon-lightUpgrade exim4-daemon-customUpgrade exim4-daemon-heavy | Nov 8, 2024 | Dec 14, 2010 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub