Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Email Security

Critical Exim Flaw Allows Attackers to Deliver Malicious Executables to Mailboxes

Successful exploitation could allow attackers to deliver executable attachments to inboxes.

A critical vulnerability in over 1.5 million internet-accessible Exim mail transfer agent (MTA) installations potentially allows attackers to deliver malicious executables to user mailboxes, Censys warns.

The issue, tracked as CVE-2024-39929 (CVSS score of 9.1) and impacting RFC 2231 header parsing, results in filenames being incorrectly parsed, which could allow remote attackers to bypass the filename extension-blocking protection mechanisms.

Successful exploitation of the security defect could allow attackers to deliver executable attachments to inboxes, which could lead to code execution and system compromise, if the user opens the attachment.

Proof-of-concept (PoC) code targeting the bug has been released publicly, but no exploitation attempts have been observed yet, Censys says.

According to the attack surface management firm, of the over 6.5 million SMTP mail servers accessible from the internet it has discovered, roughly 4.8 million are running Exim.

“As of July 10, 2024, Censys observes 1,567,109 publicly exposed Exim servers running a potentially vulnerable version (4.97.1 or earlier), concentrated mostly in the United States, Russia, and Canada,” the cybersecurity firm says.

Advertisement. Scroll to continue reading.

The vulnerability was disclosed last month and was addressed in Exim MTA version 4.98, but most internet-facing servers remain unpatched, Censys warns. As of July 10, only 82 Exim MTA installations were running a patched release.

Censys has released resources to help organizations identify public-facing Exim instances running a potentially vulnerable release, urging them to update to a patched iteration as soon as possible.

Vulnerabilities in Exim, which is widely used for receiving and relying emails, are known to have been exploited by threat actors in the wild.

Related: Vulnerabilities Exposed Millions of Cox Modems to Remote Hacking

Related: Unpatched Exim Vulnerabilities Expose Many Mail Servers to Attacks

Related: Over 4,000 Vulnerable Pulse Connect Secure Hosts Exposed to Internet

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Delve into big-picture strategies to reduce attack surfaces, improve patch management, conduct post-incident forensics, and tools and tricks needed in a modern organization.

Register

Organizations are investing heavily in third-party risk management, but breaches, delays, and blind spots continue to persist. Join this live webinar as we examine the gap between how organizations think their third-party risk programs are performing and what’s actually happening in practice.

Register

People on the Move

Joe Chen has become Chief Technology Officer at Trellix.

Usercentrics has named Pawan Hegde as COO and Elena Ignatova as CPTO.

SecureAuth has named Mark van Oppen as Chief Revenue Officer.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.