Executive brief
A flaw in the Exim Mail Transfer Agent (MTA) involves improper validation of recipient addresses in the deliver_message() function within /src/deliver.c. This vulnerability can allow a remote attacker to execute arbitrary commands on the host.
Affected products
- Exim Exim 4.87 to 4.91 (inclusive)
Timeline
- 2019-06-05: disclosed: Initial public disclosure via mailing lists.
- 2022-01-10: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.