CVE-2019-10149

A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message() function in...

Basic Information

CVE State
PUBLISHED
Reserved Date
March 27, 2019
Published Date
June 05, 2019
Last Updated
February 07, 2025
Vendor
exim
Product
exim
Description
A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message() function in /src/deliver.c may lead to remote command execution.

CVSS Scores

CVSS v3.0

9.0 - CRITICAL

Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H

SSVC Information

Exploitation
active
Technical Impact
total

Exploit Status

Exploited in the Wild
Yes (added 2022-01-10 00:00:00 UTC) Source
Proof of Concept Available
Yes (added 2024-09-06 16:21:17 UTC) Source

Known Exploited Vulnerability Information

Source Added Date
CISA 2022-01-10 00:00:00 UTC

Scanner Integrations

Potential Proof of Concepts

Warning: These PoCs have not been tested and could contain malware. Use at your own risk.

exim4_deliver_message_priv_esc

Type: metasploit • Created: Unknown

Metasploit module for CVE-2019-10149

qlusec/CVE-2019-10149

Type: github • Created: 2024-09-06 16:21:17 UTC • Stars: 0

test POC for CVE-2019-10149

hyim0810/CVE-2019-10149

Type: github • Created: 2023-10-25 02:25:17 UTC • Stars: 0

CVE-2019-10149

Dilshan-Eranda/CVE-2019-10149

Type: github • Created: 2020-05-12 15:11:54 UTC • Stars: 0

SNP Assignment on a Linux vulnerability

Diefunction/CVE-2019-10149

Type: github • Created: 2019-10-27 01:03:11 UTC • Stars: 16

CVE-2019-10149 : A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message() function in /src/deliver.c may lead to remote command execution.

darsigovrustam/CVE-2019-10149

Type: github • Created: 2019-10-21 08:13:27 UTC • Stars: 4

Instructions for installing a vulnerable version of Exim and its expluatation

AzizMea/CVE-2019-10149-privilege-escalation

Type: github • Created: 2019-06-27 01:34:41 UTC • Stars: 9

CVE-2019-10149 privilege escalation

aishee/CVE-2019-10149-quick

Type: github • Created: 2019-06-14 14:02:43 UTC • Stars: 1

Simple Bash shell quick fix CVE-2019-10149

MNEMO-CERT/PoC--CVE-2019-10149_Exim

Type: github • Created: 2019-06-13 23:21:53 UTC • Stars: 14

PoC for CVE-2019-10149, this vulnerability could be xploited betwen 4-87 to 4.91 version of Exim server.

cowbe0x004/eximrce-CVE-2019-10149

Type: github • Created: 2019-06-12 03:47:16 UTC • Stars: 13

simple python socket connection to test if exim is vulnerable to CVE-2019-10149. The payload simply touch a file in /tmp/eximrce.