V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsDocs
CVE-2010-4345
DEB
High KEVConfirmedExploit available

Exim 4.72 and earlier allows local users to gain privileges by leveraging the ability of the exim user account to specify an alternate conf…

CVSS
7.8
High
EPSS
0.07
p91
Published
2010-01-01
Updated
2022-03-25
Description

Exim 4.72 and earlier allows local users to gain privileges by leveraging the ability of the exim user account to specify an alternate configuration file with a directive that contains arbitrary commands, as demonstrated by the spool_directory directive.

Tags · CWE
KEV
CWE-77
CWE-78
CAPEC-6
CAPEC-15
CAPEC-40
CAPEC-43
CAPEC-75
CAPEC-76
CAPEC-88
CAPEC-108
CAPEC-136
CAPEC-183
CAPEC-248
Affected products
Debian_linux
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Timeline
2010-01-01
Published
2022-03-25
Added to KEV
2022-03-25
Updated
CVSS 3.1 breakdown
Attack Vector
AV: L
Local (L)
Attack Complexity
AC: L
Low (L)
Privileges Required
PR: L
Low (L)
User Interaction
UI: N
None (N)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: H
High (H)
Integrity Impact
I: H
High (H)
Availability Impact
A: H
High (H)
Exploit indicators
EPSS
0.065 · p91
Known exploited (KEV)
Yes
Known exploits — Сканер-ВС
CVE-2010-4345
cisa · https://www.cisa.gov/known-exploited-vulnerabilities-catalog
Enterprise
16925
exploitdb · https://www.exploit-db.com/exploits/16925
Enterprise
Affected software
ProductVendorStatus
eximExploited
eximExploited
exim4Exploited
exim4Exploited
debian_linux*Exploited
exim*Exploited
opensuse*Exploited
ubuntu_linux*Exploited
Source databases
DEB
CVE
RED
UBU