← back
CVE-2025-30232highCWE-416

CVE-2025-30232

21Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 8.1epss 0.5%
exploitation probability
0.5%top 59% of all CVEs
observed exploitation
nono source reports it
In short

Exim mail server has a use-after-free memory vulnerability that could let users with command-line access gain higher privileges on the system. This happens when the software tries to use memory that has already been freed, causing unpredictable behavior.

Technical detail

A use-after-free condition exists in Exim versions 4.96-4.98.1 where freed memory is accessed during execution, triggered by local command-line invocation. This memory safety issue enables privilege escalation for authenticated command-line users due to improper memory management during program flow.

Summary generated and translated by AI from the official description.
A use-after-free in Exim 4.96 through 4.98.1 could allow users (with command-line access) to escalate privileges.
CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Affected products
Exim · Exim