QID 50110

Date Published: 2021-05-04

QID 50110: Exim Mail Server Multiple Vulnerabilities (21Nails)(Generic)

Exim is a mail transfer agent (MTA) used on Unix-like operating systems. Exim is free software and it aims to be a general and flexible mailer with extensive facilities for checking incoming e-mail.

Qualys Research Team has discovered 21 vulnerabilities (11 local vulnerabilities and 10 remote vulnerabilities) that affect Exim mail Server. It has been given the name 21Nails. The bugs can be leveraged to elevate privileges to root, execute code remotely among other attacks.

Affected Versions:
Exim versions prior to 4.94.2

QID Detection Logic (Unauthenticated):
The QID checks for the SMTP banner to check for vulnerable versions of exim.

QID Detection Logic (Authenticated):
The QID checks for vulnerable versions of exim by running command "exim --version".

Successful exploitation will allow remote code execution, privilege escalation, file deletion etc.

  • CVSS V3 rated as Critical - 8.8 severity.
  • CVSS V2 rated as Critical - 10 severity.
  • Solution
    Customer are advised to update to Exim version 4.94.2 or later.

    Vendor References
    Software Advisories
    Advisory ID Software Component Link
    Exim downloads URL Logo www.exim.org/mirrors.html