Executive brief
Exim 4.72 and earlier allows local users to escalate privileges by specifying an alternate configuration file. The vulnerability stems from the ability of the exim user account to use directives, such as spool_directory, that contain arbitrary commands.
Affected products
- Exim Exim 4.72 and earlier
Timeline
- 2010-12-07: advisory: Vendor advisory published by Exim.
- 2010-12-09: patched: Patch information disclosed in mailing lists.
- 2022-03-25: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.
- 2022-03-25: disclosed: NVD publication date.