Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Email Security

Critical Exim Flaw Allows Attackers to Deliver Malicious Executables to Mailboxes

Successful exploitation could allow attackers to deliver executable attachments to inboxes.

A critical vulnerability in over 1.5 million internet-accessible Exim mail transfer agent (MTA) installations potentially allows attackers to deliver malicious executables to user mailboxes, Censys warns.

The issue, tracked as CVE-2024-39929 (CVSS score of 9.1) and impacting RFC 2231 header parsing, results in filenames being incorrectly parsed, which could allow remote attackers to bypass the filename extension-blocking protection mechanisms.

Successful exploitation of the security defect could allow attackers to deliver executable attachments to inboxes, which could lead to code execution and system compromise, if the user opens the attachment.

Proof-of-concept (PoC) code targeting the bug has been released publicly, but no exploitation attempts have been observed yet, Censys says.

According to the attack surface management firm, of the over 6.5 million SMTP mail servers accessible from the internet it has discovered, roughly 4.8 million are running Exim.

“As of July 10, 2024, Censys observes 1,567,109 publicly exposed Exim servers running a potentially vulnerable version (4.97.1 or earlier), concentrated mostly in the United States, Russia, and Canada,” the cybersecurity firm says.

Advertisement. Scroll to continue reading.

The vulnerability was disclosed last month and was addressed in Exim MTA version 4.98, but most internet-facing servers remain unpatched, Censys warns. As of July 10, only 82 Exim MTA installations were running a patched release.

Censys has released resources to help organizations identify public-facing Exim instances running a potentially vulnerable release, urging them to update to a patched iteration as soon as possible.

Vulnerabilities in Exim, which is widely used for receiving and relying emails, are known to have been exploited by threat actors in the wild.

Related: Vulnerabilities Exposed Millions of Cox Modems to Remote Hacking

Related: Unpatched Exim Vulnerabilities Expose Many Mail Servers to Attacks

Related: Over 4,000 Vulnerable Pulse Connect Secure Hosts Exposed to Internet

Written By

Ionut Arghire is an international correspondent for SecurityWeek.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join this live webinar for a practical framework for evolving your AI security program from a single application to an enterprise AI ecosystem and autonomous agents.

Register

In this live webinar, learn how to define your minimum viable business, identify the systems it depends on, measure actual recovery time against business requirements, and present the gaps to the board as measurable risk.

Register

People on the Move

Trellix has named David Pieterse as Chief Operating Officer GTM and David Soto as Chief Information Security Officer.

Mike Marshall has been appointed State Chief Information Security Officer at the California Department of Technology.

Devi Nair has been appointed Director of Cybersecurity Programs at Aspen Digital.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.