New Exim Vulnerability Enables Arbitrary Code Execution Attacks
ID: 503c9842-21d5-5296-9f05-fdfd27e30f18
STIX ID: report--503c9842-21d5-5296-9f05-fdfd27e30f18
Feed Name: Cyber Press
A critical Exim vulnerability (CVE-2026-45185, “Dead.Letter”) in Exim 4.97–4.99.2 compiled with GnuTLS and using STARTTLS+BDAT permits unauthenticated remote code execution via a use‑after‑free triggered by TLS shutdown during BDAT processing; researchers demonstrated reliable escalation from a one‑byte write to full RCE. Exim 4.99.3 fixes the root cause; mitigations include switching to OpenSSL, disabling BDAT, or restricting STARTTLS, and administrators are strongly urged to patch immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
