CVE-2010-4344criticalunder attackCWE-787

CVE-2010-4344

Published · Updated

100Vexday Risk Score

Patch now. It under exploitation confirmed by CISA and has a working public exploit.

ssvc Actcvss 9.8epss 72%
from disclosure to weapon0 days
Published on NVDDec 14
1st PoCDec 11
metasploitDec 7
CISA KEV+4119d
exploitation probability
72%top 1% of all CVEs
observed exploitation
yesCISA + VulnCheck
2 public exploit(s)
What the vendors declare (VEX)

Official vendor statements in CSAF/VEX format: whether their product is affected, already fixed, or ruled out — and why. These are the vendor's assertions, not Vexday's judgment.

Fixed
10 products (270 components)
Red Hat Enterprise Linux AS EUS (v. 4.7) · Red Hat Enterprise Linux AS version 4 · Red Hat Enterprise Linux Desktop version 4 · Red Hat Enterprise Linux ES EUS (v. 4.7) · Red Hat Enterprise Linux ES version 4 · and others 5
Action required by CISAfederal deadline: 2022-04-15

Apply updates per vendor instructions.

In short

Exim email server has a critical flaw where a specially crafted email with certain headers can cause a buffer overflow, allowing attackers to run arbitrary code on the server through SMTP.

Technical detail

Heap-based buffer overflow in the string_vformat function in Exim <4.70 exploitable via SMTP by sending two consecutive MAIL commands followed by a large message with crafted headers; improper rejection logging triggers the memory corruption, enabling remote code execution without authentication.

Summary generated and translated by AI from the official description.

The full analysis of this CVE is available in Portuguese →

Heap-based buffer overflow in the string_vformat function in string.c in Exim before 4.70 allows remote attackers to execute arbitrary code via an SMTP session that includes two MAIL commands in conjunction with a large message containing crafted headers, leading to improper rejection logging.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.