logo

Critical and high severity Exim vulnerabilities: everything you need to know

ID: 24f1d379-9085-5e5c-95c9-48a653c5bf80

STIX ID: report--24f1d379-9085-5e5c-95c9-48a653c5bf80

Feed Name: Wiz Blog

Threat Score
80/100

Date Published: 2023-10-02

Date Updated: 2026-05-01

...
...

Multiple critical and high-severity vulnerabilities in the Exim Mail Transfer Agent—particularly CVE-2023-42115 (CVSS 9.8)—can allow unauthenticated remote code execution when specific features (such as EXTERNAL authentication, SPA/NTLM, certain ACL SPF conditions, or untrusted proxy/DNS setups) are enabled; vendors have issued patches for some CVEs (Exim 4.96.1 / 4.97) and provided workarounds (disable affected features or restrict access), but several issues remain unpatched and exploitation in the wild is expected.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.