Junglewise Threat Intelligence

CVE-2019-10149: Exim Mail Transfer Agent (MTA) Improper Input Validation

CVE-2019-10149 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2022-01-10

Technologies: Exim. Vendors: Exim.

Executive brief

A flaw in the Exim Mail Transfer Agent (MTA) involves improper validation of recipient addresses in the deliver_message() function within /src/deliver.c. This vulnerability can allow a remote attacker to execute arbitrary commands on the host.

Affected products

  • Exim Exim 4.87 to 4.91 (inclusive)

Timeline

  • 2019-06-05: disclosed: Initial public disclosure via mailing lists.
  • 2022-01-10: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.