CVE-2020-28007: High severity sa-exim vulnerability
Published May 6, 2021
·Updated
Exim 4 before 4.94.2 allows Execution with Unnecessary Privileges. Because Exim operates as root in the log directory (owned by a non-root user), a symlink or hard link attack allows overwriting critical root-owned files anywhere on the filesystem.
Affected Software
1 affected component
Exim Exim>=4.00<4.94.2
Event History
May 6, 2021
CVE Published
via MITRE·02:58 AM
Data Sourced
via MITRE·02:58 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID of this vulnerability?
The vulnerability ID is CVE-2020-28007.
2
What is the severity of CVE-2020-28007?
The severity of CVE-2020-28007 is high with a CVSS score of 7.8.
3
What is the affected software?
The affected software is Exim version 4 before 4.94.2.
4
What is the description of CVE-2020-28007?
CVE-2020-28007 allows execution with unnecessary privileges in Exim 4 before 4.94.2, which can lead to overwriting critical root-owned files.
5
How can this vulnerability be exploited?
This vulnerability can be exploited through a symlink or hard link attack in the log directory, which allows overwriting critical root-owned files.