logo

Exim exploitation by Sandworm (Campaign)

ID: f4580ede-7aa7-5984-a3b5-aaa172136196

STIX ID: report--f4580ede-7aa7-5984-a3b5-aaa172136196

Feed Name: Wiz Cloud Threat Landscape

Threat Score
80/100

Date Published: 2020-05-28

Date Updated: 2026-05-01

Author: [email protected] (Wiz Threat Research)

...
...

On May 28, 2020 the NSA released an advisory reporting that the Russian APT group Sandworm exploited CVE-2019-10149 in the Exim Mail Transfer Agent; an unauthenticated attacker can send a crafted email to execute commands with root privileges, enabling installation of software, modification of data, and creation of accounts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.