Critical Exim Mail Server Vulnerability Exposes Millions to Malicious Attachments
ID: cd59ffb7-4a76-54eb-954a-920df9607dbe
STIX ID: report--cd59ffb7-4a76-54eb-954a-920df9607dbe
Feed Name: The Hacker News
A critical Exim vulnerability (CVE-2024-39929, CVSS 9.1) in versions through 4.97.1 misparses multiline RFC 2231 header filenames, enabling remote attackers to bypass $mime_filename extension-blocking and potentially deliver executable attachments to users' mailboxes; approximately 1,563,085 internet-accessible Exim servers may be vulnerable and the issue is fixed in Exim 4.98. While there are no reports of active exploitation, administrators are advised to apply the patch promptly to mitigate the risk.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
