KEVIntel
9.0
CVSS
Critical

CVE-2019-10149

PUBLISHED

A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message() function in...

Exploited in the wild Remote No user interaction
Vendor
exim
Product
exim
Published
Jun 05, 2019
EPSS

Description

A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message() function in /src/deliver.c may lead to remote command execution.

cisa metasploit

CVSS scores

CVSS v3.0 9.0 Critical

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H

Exploitation status

Exploited in the wild

Recorded 2022-01-10 00:00:00 UTC · Source

SSVC decision points

Exploitation
active
Automatable
No
Technical impact
total

Known exploited vulnerability sources

Catalogues that list this CVE as a known exploited vulnerability.

Source Added
CISA Jan 10, 2022
CISA Jan 10, 2022

Potential proof of concepts

These PoCs are unverified and could contain malware. Use at your own risk.

exim4_deliver_message_priv_esc

metasploit · Created Unknown

Metasploit module for CVE-2019-10149

qlusec/CVE-2019-10149

github · Created 2024-09-06 16:21:17 UTC · 0 stars

test POC for CVE-2019-10149

hyim0810/CVE-2019-10149

github · Created 2023-10-25 02:25:17 UTC · 0 stars

CVE-2019-10149

Dilshan-Eranda/CVE-2019-10149

github · Created 2020-05-12 15:11:54 UTC · 0 stars

SNP Assignment on a Linux vulnerability

Diefunction/CVE-2019-10149

github · Created 2019-10-27 01:03:11 UTC · 16 stars

CVE-2019-10149 : A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message() function in /src/deliver.c may lead to remote command execution.

darsigovrustam/CVE-2019-10149

github · Created 2019-10-21 08:13:27 UTC · 4 stars

Instructions for installing a vulnerable version of Exim and its expluatation

AzizMea/CVE-2019-10149-privilege-escalation

github · Created 2019-06-27 01:34:41 UTC · 9 stars

CVE-2019-10149 privilege escalation

aishee/CVE-2019-10149-quick

github · Created 2019-06-14 14:02:43 UTC · 1 stars

Simple Bash shell quick fix CVE-2019-10149

MNEMO-CERT/PoC--CVE-2019-10149_Exim

github · Created 2019-06-13 23:21:53 UTC · 14 stars

PoC for CVE-2019-10149, this vulnerability could be xploited betwen 4-87 to 4.91 version of Exim server.

cowbe0x004/eximrce-CVE-2019-10149

github · Created 2019-06-12 03:47:16 UTC · 13 stars

simple python socket connection to test if exim is vulnerable to CVE-2019-10149. The payload simply touch a file in /tmp/eximrce.

Timeline

  • CVE ID Reserved

  • CVE Published to Public

  • Added to KEVIntel

  • Added to KEVIntel

  • Detected by Metasploit