CVE-2019-10149criticalunder attackCWE-78

CVE-2019-10149: critical vulnerability in exim

Published · Updated

100Vexday Risk Score

Patch now. It under exploitation confirmed by CISA and has a working public exploit.

ssvc Actcvss 9epss 100%
from disclosure to weapon0 days
Published on NVDJun 5
1st PoCJul 12
metasploitJun 5
CISA KEV+950d
exploitation probability
100%top 1% of all CVEs
observed exploitation
yesCISA + VulnCheck
39 public exploit(s)
What the vendors declare (VEX)

Official vendor statements in CSAF/VEX format: whether their product is affected, already fixed, or ruled out — and why. These are the vendor's assertions, not Vexday's judgment.

Not affected
1 product — because the vulnerable code is not present in the product
Red Hat Enterprise Linux 5
Action required by CISAfederal deadline: 2022-07-10

Apply updates per vendor instructions.

In short

Exim email servers versions 4.87 to 4.91 fail to properly validate recipient addresses, allowing attackers to execute arbitrary commands on the server remotely.

Technical detail

A command injection vulnerability exists in the deliver_message() function within /src/deliver.c where insufficient input validation on recipient addresses permits unauthenticated remote code execution. The attack vector requires sending a specially crafted email with a malicious recipient address; exploitation is trivial as Exim processes untrusted input directly in shell contexts.

Summary generated and translated by AI from the official description.

The full analysis of this CVE is available in Portuguese →

A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message() function in /src/deliver.c may lead to remote command execution.
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Affected products
exim · exim
public PoCs found — 39✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/47307exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/46996exploitdbwww.exploit-db.com/exploits/46974unverifiedgithubgithub.com/bananaphones/exim-rce-quickfix★ 22githubgithub.com/Diefunction/CVE-2019-10149★ 20githubgithub.com/MNEMO-CERT/PoC--CVE-2019-10149_Exim★ 14githubgithub.com/cowbe0x004/eximrce-CVE-2019-10149★ 14githubgithub.com/AzizMea/CVE-2019-10149-privilege-escalation★ 9githubgithub.com/darsigovrustam/CVE-2019-10149★ 5githubgithub.com/Chris-dev1/exim.exp★ 4githubgithub.com/cloudflare/exim-cve-2019-10149-data★ 3githubgithub.com/Brets0150/StickyExim★ 3githubgithub.com/uyerr/PoC_CVE-2019-10149--rce★ 1githubgithub.com/Stick-U235/CVE-2019-10149-Exploit★ 1githubgithub.com/aishee/CVE-2019-10149-quick★ 1githubgithub.com/hyim0810/CVE-2019-10149★ 0githubgithub.com/Dilshan-Eranda/CVE-2019-10149★ 0githubgithub.com/rahmadsandy/EXIM-4.87-CVE-2019-10149★ 0githubgithub.com/VoyagerOnne/Exim-CVE-2019-10149★ 0githubgithub.com/CybersRMUTL/CVE-2019-10149-Exim4-RCE★ 0githubgithub.com/qlusec/CVE-2019-10149★ 0githubgithub.com/Ambrella-Security/CVE-2019-10149★ 0vulncheckvulncheck.com/xdb/70326cca6d27unverifiedvulncheckvulncheck.com/xdb/ca604e67a881unverifiedvulncheckvulncheck.com/xdb/49992cce5b1cunverifiedvulncheckvulncheck.com/xdb/bb70225786a3unverifiedvulncheckvulncheck.com/xdb/ca73aedc1e14unverifiedvulncheckvulncheck.com/xdb/ee883571c18eunverifiedvulncheckvulncheck.com/xdb/0e9dcf2ac58cunverifiedvulncheckvulncheck.com/xdb/2e73af25d4a9unverifiedvulncheckvulncheck.com/xdb/12238eca37ffunverifiedvulncheckvulncheck.com/xdb/eeb36c51b81dunverifiedvulncheckvulncheck.com/xdb/16dc2d42770cunverifiedcve_referencepacketstormsecurity.com/files/154198/Exim-4.91-Local-Privilege-Escalation.htmlunverifiedcve_referencepacketstormsecurity.com/files/153312/Exim-4.91-Local-Privilege-Escalation.htmlunverifiedvulncheckvulncheck.com/xdb/20346f31ab54unverifiedcve_referencepacketstormsecurity.com/files/153218/Exim-4.9.1-Remote-Command-Execution.htmlunverifiedvulncheckvulncheck.com/xdb/d40c82e4a679unverifiedvulncheckvulncheck.com/xdb/1a1f3a4ff3c8unverified
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.