Exim Vulnerability Affecting Public Email Servers
A vulnerability affecting the Exim mail transfer agent (MTA) exposes 56% of all publicly available email servers to remote code execution or denial-of-service (DoS) attacks.
This content has been archived
This article no longer conforms to NHS Digital's standards for cyber alerts, and may contain outdated or inaccurate information. Use of this information contained in this page is at your own risk
Summary
A vulnerability affecting the Exim mail transfer agent (MTA) exposes 56% of all publicly available email servers to remote code execution or denial-of-service (DoS) attacks.
Affected platforms
The following platforms are known to be affected:
Threat details
An error in the way Exim parses BDAT (an alternative to the Simple Mail Transfer protocol DATA command) data headers affects how the MTA manages “chunking”; or breaking down, handling and reconstructing emails. An attacker may exploit this by tampering with the header, which can lead to the MTA reading from other memory locations. This can result in remote code execution.
Remediation steps
| Type | Step |
|---|---|
|
Last edited: 17 February 2020 11:30 am