⚠ Actively exploited
Added to CISA KEV on 2022-01-10. Federal agencies required to patch by 2022-07-10. Required action: Apply updates per vendor instructions..

CVE-2019-10149OS Command Injection in Exim

Severity
9.8CRITICALNVD
EPSS
93.9%
top 0.12%
CISA KEV
KEV
Added 2022-01-10
Due 2022-07-10
Exploit
Exploited in wild
Active exploitation observed
Timeline
PublishedJun 5
KEV addedJan 10
KEV dueJul 10
Latest updateFeb 2
CISA Required Action: Apply updates per vendor instructions.

Description

A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message() function in /src/deliver.c may lead to remote command execution.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages3 packages

debiandebian/exim4< exim4 4.92~RC3-1 (bookworm)
NVDexim/exim4.874.91
CVEListV5exim/exim4.92

Also affects: Debian Linux 9.0, Ubuntu Linux 18.04, 18.10

Patches

🔴Vulnerability Details

3
GHSA
GHSA-5r7w-xvrp-rg22: A flaw was found in Exim versions 42022-05-24
OSV
CVE-2019-10149: A flaw was found in Exim versions 42019-06-05
VulnCheck
Exim Mail Transfer Agent (MTA) Improper Input Validation2019

💥Exploits & PoCs

4
Exploit-DB
Exim 4.87 / 4.91 - Local Privilege Escalation (Metasploit)2019-08-26
Exploit-DB
Exim 4.87 - 4.91 - Local Privilege Escalation2019-06-17
Exploit-DB
Exim 4.87 < 4.91 - (Local / Remote) Command Execution2019-06-05
Metasploit
Exim 4.87 - 4.91 Local Privilege Escalation

🔍Detection Rules

1
Suricata
ET EXPLOIT Possible Exim 4.87-4.91 RCE Attempt Inbound (CVE-2019-10149)2019-06-07

📋Vendor Advisories

4
CISA
Exim Mail Transfer Agent (MTA) Improper Input Validation2022-01-10
Ubuntu
Exim vulnerability2019-06-05
Red Hat
exim: Remote command execution in deliver_message() function in /src/deliver.c2019-06-04
Debian
CVE-2019-10149: exim4 - A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation ...2019

🕵️Threat Intelligence

26
Qualys
Mutagen Astronomy: From Discovery to CISA Recognition—A Seven-Year Journey2026-02-02
Qualys
Mutagen Astronomy: A Linux Vulnerability’s Path to CISA KEV | Qualys2026-02-02
Tenable
From Bugs to Breaches: 25 Significant CVEs As MITRE CVE Turns 252024-10-22
Bleepingcomputer
Millions of Exim mail servers exposed to zero-day RCE attacks2023-09-29
Tenable
AA23-215A: 2022&#039;s Top Routinely Exploited Vulnerabilities2023-08-03

💬Community

2
Bugzilla
CVE-2019-10149 exim: Remote command execution in deliver_message() function in /src/deliver.c [epel-all]2019-06-04
Bugzilla
CVE-2019-10149 exim: Remote command execution in deliver_message() function in /src/deliver.c2019-05-29