Vulnerability record · CVE-2010-2075 · published 15 June 2010
CVE-2010-2075: UnrealIRCd backdoor in DEBUG3_DOLOG_SYSTEM macro allows remote command execution
Unrealircd · Unrealircd
UnrealIRCd 3.2.8.1 distributed from certain mirror sites between November 2009 and June 2010 contained an externally introduced Trojan Horse modification in the DEBUG3_DOLOG_SYSTEM macro. The tampered code lets a remote attacker execute arbitrary commands on the IRC server. Because the malicious code was shipped in the official-looking distribution, operators who downloaded from the affected mirrors ran a backdoored daemon without knowing it.
Description
UnrealIRCd 3.2.8.1, as distributed on certain mirror sites from November 2009 through June 2010, contains an externally introduced modification (Trojan Horse) in the DEBUG3_DOLOG_SYSTEM macro, which allows remote attackers to execute arbitrary commands.
AV:N/AC:L/Au:N/C:P/I:P/A:P
Automated analysis
high priorityUnauthenticated remote command execution with public exploit code and very high EPSS, though the affected distribution window is old and KEV does not list it.
What it is
UnrealIRCd 3.2.8.1 distributed from certain mirror sites between November 2009 and June 2010 contained an externally introduced Trojan Horse modification in the DEBUG3_DOLOG_SYSTEM macro. The tampered code lets a remote attacker execute arbitrary commands on the IRC server. Because the malicious code was shipped in the official-looking distribution, operators who downloaded from the affected mirrors ran a backdoored daemon without knowing it.
Impact
An attacker gains remote command execution on the IRC server, typically with the privileges of the UnrealIRCd process. That allows full compromise of the host, including data theft, further lateral movement, or use of the server as a botnet or DDoS relay.
Attack surface
Reachable over the network via the IRC service; the CVSS vector AV:N/AC:L/Au:N indicates no authentication is required. No user interaction is described in the record.
Exploitation
Not listed in CISA KEV, but EPSS is very high (0.835 probability, 99.7th percentile) and references include an Exploit-DB entry and a SecurityFocus BID tagged Exploit, indicating public exploit code exists.
What to do
- Replace any UnrealIRCd 3.2.8.1 binary obtained from mirror sites between November 2009 and June 2010 with a clean build from the official UnrealIRCd source or vendor.
- Verify the integrity of the installed binary against the vendor advisory and known-good hashes before trusting the host.
- If a backdoored build was running, treat the host as compromised: rebuild it and rotate all credentials and keys that were present.
- Restrict IRC service exposure to trusted networks and monitor for unexpected outbound connections from the IRC host.
Detection
- Search hosts for UnrealIRCd 3.2.8.1 binaries and compare hashes against the official release.
- Monitor IRC server process for unexpected child processes or shell execution, which would indicate the backdoor being triggered.
- Review network logs for anomalous outbound connections originating from the IRC server to unknown destinations.
- Check file timestamps and package provenance for UnrealIRCd installs from the affected mirror window.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2010-2075 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2010-2075), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.