Skip to main content

Exim Vulnerability Affecting Public Email Servers

A vulnerability affecting the Exim mail transfer agent (MTA) exposes 56% of all publicly available email servers to remote code execution or denial-of-service (DoS) attacks.
Report a cyber attack: call 0300 303 5222 or email [email protected]

This content has been archived

This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk

Summary

A vulnerability affecting the Exim mail transfer agent (MTA) exposes 56% of all publicly available email servers to remote code execution or denial-of-service (DoS) attacks.

Affected platforms

The following platforms are known to be affected:

Threat details

An error in the way Exim parses BDAT (an alternative to the Simple Mail Transfer protocol DATA command) data headers affects how the MTA manages “chunking”; or breaking down, handling and reconstructing emails. An attacker may exploit this by tampering with the header, which can lead to the MTA reading from other memory locations. This can result in remote code execution.


Remediation steps

Type Step
  • Administrators are encouraged to review Exim Update 4.89.1 and apply the patch.
  • Alternatively, if the patch is unable to be applied, a workaround has been provided by Exim.

Last edited: 17 February 2020 11:30 am