V
Scaner-VS
HomeCatalogSourcesCWECAPECATT&CKMitigationsProductsVendorsDocs
CVE-2023-42117
ANC
High

Exim Improper Neutralization of Special Elements Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute…

CVSS
8.1
High
EPSS
0.06
p91
Published
2023-01-01
Updated
2023-01-01
Description

Exim Improper Neutralization of Special Elements Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Exim. Authentication is not required to exploit this vulnerability. The specific flaw exists within the smtp service, which listens on TCP port 25 by default. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-17554.

Tags · CWE
RCEPre-auth
CWE-119
CWE-138
CWE-77
CAPEC-8
CAPEC-9
CAPEC-10
CAPEC-14
CAPEC-15
CAPEC-24
CAPEC-34
CAPEC-40
CAPEC-42
CAPEC-43
CAPEC-44
CAPEC-45
CAPEC-46
CAPEC-47
CAPEC-75
CAPEC-76
CAPEC-100
CAPEC-105
CAPEC-123
CAPEC-136
CAPEC-183
CAPEC-248
Affected products
Exim < 4.96.2
CVSS vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Timeline
2023-01-01
Published
2023-01-01
Updated
CVSS 3.1 breakdown
Attack Vector
AV: N
Network (N)
Attack Complexity
AC: H
High (H)
Privileges Required
PR: N
None (N)
User Interaction
UI: N
None (N)
Scope
S: U
Unchanged (U)
Confidentiality Impact
C: H
High (H)
Integrity Impact
I: H
High (H)
Availability Impact
A: H
High (H)
Exploit indicators
EPSS
0.057 · p91
Known exploited (KEV)
No
Known exploits — Сканер-ВС
No Сканер-ВС checks registered for this vulnerability yet.
Affected products
ProductVendorStatus
Tracked
exim4Tracked
exim4Tracked
exim4Tracked
exim4Tracked
exim4Tracked
exim4Tracked
exim4Tracked
exim4Tracked
exim4Tracked
exim4Tracked
exim4Tracked
exim4Tracked
exim4Tracked
exim4Tracked
exim*Tracked
Source databases
ANC
AST
DEB
CVE
UBU
Related vulnerabilities