Exim mail servers left open to zero-day attacks for over a year
A major flaw in Exim’s mail transfer agent (MTA) software has been detected that has gone without a patch for more than a year.
Researchers from Trend Micro’s Zero Day Initiative were tipped off by an anonymous researcher in June last year, about an out-of-bounds write weakness discovered in the SMTP service, BleepingComputer reported.
Exim is an MTA that runs in the background of email servers, and hackers can use it to run malware on vulnerable endpoints.
Used by Russian hackers
That vulnerability is being tracked as CVE-2023-42115, and can be used to crash software and corrupt valuable data, but more importantly – it can be used to run malicious code on vulnerable servers.
Exim was reportedly first notified about the flaw in June 2022, and then again in May 2023, but apparently to no avail. Given Exim’s failure to address it, Trend Micro Zero Day Initiative has now published an advisory describing the flaw, and detailing its discussion with Exim over the months.
According to BleepingComputer, MTA servers like Exim are a popular target among hackers as they can be accessed remotely and used to move into the wider corporate network. It’s also apparently the “world’s most popular MTA software, installed on more than 56% of 602,000 internet-connected mail servers” (342,000). This is mostly because it comes bundled with many popular Linux distros including Debian and Red Hat.
Three years ago, Sandworm (a Russian state-sponsored threat actor) was using a flaw found in Exim to infiltrate endpoints, the NSA warned at the time.
“The Russian actors, part of the General Staff Main Intelligence Directorate’s (GRU) Main Center for Special Technologies (GTsST), have used this exploit to add privileged users, disable network security settings, execute additional scripts for further network exploitation; pretty much any attacker’s dream access – as long as that network is using an unpatched version of Exim MTA,” the NSA said.
Via BleepingComputer
More from TechRadar Pro
A major flaw in Exim’s mail transfer agent (MTA) software has been detected that has gone without a patch for more than a year. Researchers from Trend Micro’s Zero Day Initiative were tipped off by an anonymous researcher in June last year, about an out-of-bounds write weakness discovered in the…
Recent Posts
- How to watch Spain vs Iraq: Free Streams & TV Channels for World Cup 2026 warm-up match
- TSMC struggles to keep up with AI demand: ‘We can only support so much’
- We’re giving away a Prime Day grab bag loaded with over $800 of free tech
- Here’s what you should and shouldn’t plug into a TV USB port
- Amazon’s new Proteus warehouse robot is fully autonomous
Archives
- June 2026
- May 2026
- April 2026
- March 2026
- February 2026
- January 2026
- December 2025
- November 2025
- October 2025
- September 2025
- August 2025
- July 2025
- June 2025
- May 2025
- April 2025
- March 2025
- February 2025
- January 2025
- December 2024
- November 2024
- October 2024
- September 2024
- August 2024
- July 2024
- June 2024
- May 2024
- April 2024
- March 2024
- February 2024
- January 2024
- December 2023
- November 2023
- October 2023
- September 2023
- August 2023
- July 2023
- June 2023