ZDI-23-1471: (0Day) Exim Improper Neutralization of Special Elements Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Exim. Authentication is not required to exploit this vulnerability. The specific flaw exists within the smtp service, which listens on TCP port 25 by default. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process.
Other sources
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Exim. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.1. The following CVEs are assigned: CVE-2023-42117.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is ZDI-23-1471.
What is the severity of vulnerability ZDI-23-1471?
The severity of vulnerability ZDI-23-1471 is high with a CVSS score of 8.1.
Which software is affected by vulnerability ZDI-23-1471?
The software affected by vulnerability ZDI-23-1471 is Exim.
What is the impact of vulnerability ZDI-23-1471?
Vulnerability ZDI-23-1471 allows remote attackers to execute arbitrary code on affected Exim installations without requiring authentication.
How can I fix vulnerability ZDI-23-1471?
To fix vulnerability ZDI-23-1471, it is recommended to apply the latest security patches and updates provided by Exim.