Email Security

Unpatched Exim Vulnerabilities Expose Many Mail Servers to Attacks 

Patches are being developed for serious Exim vulnerabilities that could expose many mail servers to attacks. 

Patches are being developed for serious Exim vulnerabilities that could expose many mail servers to attacks. 

The existence of several unpatched vulnerabilities impacting Exim mail transfer agent (MTA) installations was disclosed last week, more than one year after they were initially reported to developers. 

Trend Micro’s Zero Day Initiative (ZDI) learned about six Exim vulnerabilities last year and reported the findings to the MTA software’s developers in June 2022. However, Exim developers have only now started working on patches, with accusations being made by both sides.

Exim, a piece of software used to receive and relay emails, is present on hundreds of thousands of servers. Vulnerabilities affecting the software can be highly valuable to threat actors, which have been known to exploit Exim flaws in their attacks. 

ZDI last week released six individual advisories describing the flaws, reported to the company by an anonymous researcher. The most serious of them, rated ‘critical’ and tracked as CVE-2023-42115, can be exploited by a remote, unauthenticated attacker to execute arbitrary code.

Three other flaws, classified as ‘high severity’ and tracked as CVE-2023-42116, CVE-2023-42117 and CVE-2023-42118, can also be exploited for remote code execution without authentication.

The remaining two issues have a lower severity rating and their exploitation can lead to information disclosure.

Advertisement. Scroll to continue reading.

According to ZDI’s timeline, the vulnerabilities were reported to Exim developers in June 2022 and ZDI reached out for an update in late April 2023, with the bug reports being resent to Exim in May. 

ZDI made its advisories public on September 27 and a public discussion regarding the flaws was initiated late last week on the Openwall mailing list. 

Exim is working on patches and says they should become available shortly, though there still seems to be some confusion within Exim on what exactly has been reported via ZDI. Developers claim the vulnerabilities can only be exploited if certain features are used. 

Exim developers have complained that ZDI failed to provide needed clarifications between its initial report in June 2022 and May 2023. 

Some have argued that it has still taken Exim developers a long time to start addressing the flaws, even if it only learned about them in May. 

In response to the Exim team’s complaints, ZDI said, “The ZDI reached out multiple times to the developers regarding multiple bug reports with little progress to show for it. After our disclosure timeline was exceeded by many months, we notified the maintainer of our intent to publicly disclose these bugs, at which time we were told, ‘you do what you do’.” 

Related: NSA: Russian Agents Have Been Hacking Major Email Program

Related: Critical Remote Code Execution Vulnerability Patched in Exim Email Server

Related Content

Email Security

‘PoisonSeed’ phishing campaign targets CRM and bulk email providers to distribute “crypto seed phrase” messages.

Data Breaches

An email security incident at Chord Specialty Dental Partners, a US dental service organization, has impacted more than 170,000 people. 

Artificial Intelligence

Microsoft offers $10,000 in rewards to researchers who can manipulate a realistic simulated LLM-integrated email client.

Email Security

Cybercriminals are abusing DocuSign APIs to send bogus email messages that bypass protections such as spam and phishing filters.

Email Security

The Internet Archive has suffered an email hack while working to restore services impacted by the recent cyberattacks.

Email Security

A critical-severity vulnerability in Zimbra has been exploited in the wild to deploy a web shell on vulnerable servers.

Email Security

SecurityWeek spoke with Mike Britton, CISO at Abnormal Security, to understand what the company has learned about current social engineering and phishing attacks.

Cybersecurity Funding

Email security firm Abnormal Security has raised $250 million in a Series D funding round at a $5.1 billion valuation. 

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version