Critical and high severity Exim vulnerabilities: everything you need to know
ID: 24f1d379-9085-5e5c-95c9-48a653c5bf80
STIX ID: report--24f1d379-9085-5e5c-95c9-48a653c5bf80
Feed Name: Wiz Blog
Multiple critical and high-severity vulnerabilities in the Exim Mail Transfer Agent—particularly CVE-2023-42115 (CVSS 9.8)—can allow unauthenticated remote code execution when specific features (such as EXTERNAL authentication, SPA/NTLM, certain ACL SPF conditions, or untrusted proxy/DNS setups) are enabled; vendors have issued patches for some CVEs (Exim 4.96.1 / 4.97) and provided workarounds (disable affected features or restrict access), but several issues remain unpatched and exploitation in the wild is expected.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
