CVE-2019-10149

Exim Mail Transfer Agent (MTA) Improper Input Validation

9.8
CVSS 3.1
100.0 %
EPSS (current)
2022-01-10
KEV addition
No
Ransomware

Timeline

Publication, first public exploit and KEV addition on a day axis.

Key facts

Vendor / product: Exim / Mail Transfer Agent (MTA)

Published: 2019-06-05 · Due (CISA): 2022-07-10

CWE: CWE-78 · EU list: no

Exploit references (metadata only)

SourceReferenceTitleDate
exploitdb46974Exim 4.87 < 4.91 - (Local / Remote) Command Execution2019-06-05
metasploitexploit/linux/local/exim4_deliver_message_priv_escexploit/linux/local/exim4_deliver_message_priv_esc2019-06-05
exploitdb46996Exim 4.87 - 4.91 - Local Privilege Escalation2019-06-17
exploitdb47307Exim 4.87 / 4.91 - Local Privilege Escalation (Metasploit)2019-08-26

References only — no downloads or instructions.

Sources