VulnerabilityAnalyzed
CVE-2010-4345
Exim Privilege Escalation Vulnerability
KEVHIGH 7.8EPSS 18.1%
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 15 April 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
Exim 4.72 and earlier allows local users to gain privileges by leveraging the ability of the exim user account to specify an alternate configuration file with a directive that contains arbitrary commands, as demonstrated by the spool_directory directive.
- CVSS 3.1
- 7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 18.11% probability · 97th percentile
- CISA KEV
- Listed 25 March 2022 · due 15 April 2022
- Weakness
- CWE-77
- Affected
- exim/exim · opensuse/opensuse · debian/debian linux · canonical/ubuntu linux
- Source
- secalert@redhat.com
CISA notes
Apply updates per vendor instructions. https://nvd.nist.gov/vuln/detail/CVE-2010-4345
References
- http://bugs.exim.org/show_bug.cgi?id=1044Issue Tracking, Patch
- http://lists.exim.org/lurker/message/20101209.172233.abcba158.en.htmlMailing List, Patch
- http://lists.exim.org/lurker/message/20101210.164935.385e04d0.en.htmlMailing List
- http://lists.opensuse.org/opensuse-security-announce/2010-12/msg00003.htmlMailing List, Third Party Advisory
- http://openwall.com/lists/oss-security/2010/12/10/1Mailing List
- http://secunia.com/advisories/42576Broken Link, Vendor Advisory
- http://secunia.com/advisories/42930Broken Link
- http://secunia.com/advisories/43128Broken Link
- http://secunia.com/advisories/43243Broken Link
- http://www.cpanel.net/2010/12/critical-exim-security-update.htmlBroken Link
- http://www.debian.org/security/2010/dsa-2131Mailing List, Third Party Advisory
- http://www.debian.org/security/2011/dsa-2154Mailing List, Third Party Advisory
- http://www.exim.org/lurker/message/20101207.215955.bb32d4f2.en.htmlMailing List, Vendor Advisory
- http://www.kb.cert.org/vuls/id/758489Third Party Advisory, US Government Resource
- http://www.metasploit.com/modules/exploit/unix/smtp/exim4_string_formatThird Party Advisory
- http://www.openwall.com/lists/oss-security/2021/05/04/7Mailing List
- http://www.redhat.com/support/errata/RHSA-2011-0153.htmlBroken Link
- http://www.securityfocus.com/archive/1/515172/100/0/threadedBroken Link, Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/45341Broken Link, Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id?1024859Broken Link, Third Party Advisory, VDB Entry
- http://www.theregister.co.uk/2010/12/11/exim_code_execution_peril/Press/Media Coverage, Third Party Advisory
- http://www.ubuntu.com/usn/USN-1060-1Third Party Advisory
- http://www.vupen.com/english/advisories/2010/3171Broken Link, Vendor Advisory
- http://www.vupen.com/english/advisories/2010/3204Broken Link, Vendor Advisory
- http://www.vupen.com/english/advisories/2011/0135Broken Link
- http://www.vupen.com/english/advisories/2011/0245Broken Link
- http://www.vupen.com/english/advisories/2011/0364Broken Link
- https://bugzilla.redhat.com/show_bug.cgi?id=662012Issue Tracking, Patch
- http://bugs.exim.org/show_bug.cgi?id=1044Issue Tracking, Patch
- http://lists.exim.org/lurker/message/20101209.172233.abcba158.en.htmlMailing List, Patch
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.