← Vulnerability feed

Vulnerability record · CVE-2010-4345 · published 14 December 2010

CVE-2010-4345: Exim local privilege escalation via alternate config file command injection

Exim · Exim

Exim 4.72 and earlier lets the exim user account specify an alternate configuration file whose directives can contain arbitrary commands, as shown with the spool_directory directive. A local user who can influence that configuration path can execute commands as the exim user, which is a privilege escalation on affected mail servers.

7.8 CVSS 3.1 High CISA KEV since 25 Mar 2022 EPSS 18% · top 2.9% CWE-77 · Command injection
7.8CVSS 3.1 base score, v2 6.9
18%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
4Affected product versions listed by NVD
57References
16 Jun 2026Last modified by NVD

Description

Exim 4.72 and earlier allows local users to gain privileges by leveraging the ability of the exim user account to specify an alternate configuration file with a directive that contains arbitrary commands, as demonstrated by the spool_directory directive.

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

high priorityIt is in CISA KEV with a high EPSS percentile and public exploit tooling, but requires local access and affects an old Exim version.

What it is

Exim 4.72 and earlier lets the exim user account specify an alternate configuration file whose directives can contain arbitrary commands, as shown with the spool_directory directive. A local user who can influence that configuration path can execute commands as the exim user, which is a privilege escalation on affected mail servers.

Impact

An attacker gains the privileges of the exim user account and can run arbitrary commands, potentially leading to full root compromise depending on local configuration. This is a local escalation, not remote code execution by itself.

Attack surface

Reached locally; the CVSS vector is AV:L/PR:L/UI:N, so the attacker needs a local account and low privileges, with no user interaction. No network vector or authentication bypass is described.

Exploitation

CISA KEV lists it as exploited with a 2022-04-15 remediation due date, and EPSS is 0.18105 (97th percentile), indicating meaningful exploitation activity. Reference tags include Patch and a Metasploit module link, so public exploit tooling exists.

What to do

  • Apply the vendor patch for Exim and the listed distributions (Debian, Ubuntu, openSUSE) per their advisories.
  • Restrict who can write or point Exim at alternate configuration files, and audit config file ownership and permissions.
  • Run Exim with least privilege and avoid configurations that let the exim user invoke arbitrary commands.
  • Monitor and limit local accounts on mail servers, since exploitation requires local access.

Detection

  • Audit Exim configuration files and startup arguments for unexpected alternate config paths or spool_directory values.
  • Alert on processes spawned by the exim user that are not normal mail handling activity.
  • Review local account creation and privilege changes on mail servers for signs of pre-exploitation staging.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2010-4345 to the Known Exploited Vulnerabilities catalog on 25 March 2022 as "Exim Privilege Escalation Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 15 April 2022.

Affected products

4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://bugs.exim.org/show_bug.cgi?id=1044 Issue TrackingPatch
http://lists.exim.org/lurker/message/20101209.172233.abcba158.en.html Mailing ListPatch
http://lists.exim.org/lurker/message/20101210.164935.385e04d0.en.html Mailing List
http://lists.opensuse.org/opensuse-security-announce/2010-12/msg00003.html Mailing ListThird Party Advisory
http://openwall.com/lists/oss-security/2010/12/10/1 Mailing List
http://secunia.com/advisories/42576 Broken LinkVendor Advisory
http://secunia.com/advisories/42930 Broken Link
http://secunia.com/advisories/43128 Broken Link
http://secunia.com/advisories/43243 Broken Link
http://www.cpanel.net/2010/12/critical-exim-security-update.html Broken Link
http://www.debian.org/security/2010/dsa-2131 Mailing ListThird Party Advisory
http://www.debian.org/security/2011/dsa-2154 Mailing ListThird Party Advisory
http://www.exim.org/lurker/message/20101207.215955.bb32d4f2.en.html Mailing ListVendor Advisory
http://www.kb.cert.org/vuls/id/758489 Third Party AdvisoryUS Government Resource
http://www.metasploit.com/modules/exploit/unix/smtp/exim4_string_format Third Party Advisory
http://www.openwall.com/lists/oss-security/2021/05/04/7 Mailing List
http://www.redhat.com/support/errata/RHSA-2011-0153.html Broken Link
http://www.securityfocus.com/archive/1/515172/100/0/threaded Broken LinkThird Party AdvisoryVDB Entry
http://www.securityfocus.com/bid/45341 Broken LinkThird Party AdvisoryVDB Entry
http://www.securitytracker.com/id?1024859 Broken LinkThird Party AdvisoryVDB Entry
http://www.theregister.co.uk/2010/12/11/exim_code_execution_peril/ Press/Media CoverageThird Party Advisory
http://www.ubuntu.com/usn/USN-1060-1 Third Party Advisory
http://www.vupen.com/english/advisories/2010/3171 Broken LinkVendor Advisory
http://www.vupen.com/english/advisories/2010/3204 Broken LinkVendor Advisory
http://www.vupen.com/english/advisories/2011/0135 Broken Link
http://www.vupen.com/english/advisories/2011/0245 Broken Link
http://www.vupen.com/english/advisories/2011/0364 Broken Link
https://bugzilla.redhat.com/show_bug.cgi?id=662012 Issue TrackingPatch
http://bugs.exim.org/show_bug.cgi?id=1044 Issue TrackingPatch
http://lists.exim.org/lurker/message/20101209.172233.abcba158.en.html Mailing ListPatch
http://lists.exim.org/lurker/message/20101210.164935.385e04d0.en.html Mailing List
http://lists.opensuse.org/opensuse-security-announce/2010-12/msg00003.html Mailing ListThird Party Advisory
http://openwall.com/lists/oss-security/2010/12/10/1 Mailing List
http://secunia.com/advisories/42576 Broken LinkVendor Advisory
http://secunia.com/advisories/42930 Broken Link
http://secunia.com/advisories/43128 Broken Link
http://secunia.com/advisories/43243 Broken Link
http://www.cpanel.net/2010/12/critical-exim-security-update.html Broken Link
http://www.debian.org/security/2010/dsa-2131 Mailing ListThird Party Advisory
http://www.debian.org/security/2011/dsa-2154 Mailing ListThird Party Advisory

Track CVE-2010-4345 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2025-32433Erlang/OTP SSH server missing authentication allows remote code executionErlang/OTP SSH servers before OTP-27.3.3, OTP-26.2.5.11 and OTP-25.3.2.20 mishandle SSH protocol messages, letting an unauthenticated attacker execut…KEVEPSS 99%analysed10.0CVE-2025-24201Apple WebKit out-of-bounds write allows sandbox escapeCVE-2025-24201 is an out-of-bounds write in Apple's WebKit that was addressed with improved checks. Maliciously crafted web content may break out of …KEVEPSS 3.8%analysed10.0CVE-2021-44228Apache Log4j2 JNDI lookup remote code executionApache Log4j2 versions 2.0-beta9 through 2.15.0 (excluding 2.12.2, 2.12.3, and 2.3.1) do not protect against attacker-controlled LDAP and other JNDI …KEVEPSS 100%analysed9.8CVE-2026-24061GNU Inetutils telnetd argument injection allows remote auth bypasstelnetd in GNU Inetutils through 2.7 fails to sanitize the USER environment variable, so a value such as "-f root" is passed as an argument to login …KEVEPSS 99%analysed9.8CVE-2025-39682Linux kernel TLS zero-length record handling flaw on rx_listThe Linux kernel TLS receive path mishandles zero-length records that arrive from the rx_list, breaking the assumption that a record type change cann…KEVEPSS 2.9%analysed9.8CVE-2025-24813Apache Tomcat Default Servlet path equivalence enables RCE and file disclosureApache Tomcat mishandles path equivalence for names containing an internal dot, letting a remote unauthenticated attacker write files through the Def…KEVEPSS 100%analysed9.8CVE-2024-9680Mozilla Firefox and Thunderbird use-after-free in Animation timelinesA use-after-free flaw in Animation timelines allows an attacker to execute code in the content process of Firefox and Thunderbird. Mozilla reports ex…KEVEPSS 23%analysed9.8CVE-2023-46604Apache ActiveMQ OpenWire deserialization remote code executionThe Java OpenWire protocol marshaller in Apache ActiveMQ deserializes untrusted data, letting an attacker manipulate serialized class types so the br…KEVEPSS 100%analysed

Source: NIST National Vulnerability Database (record CVE-2010-4345), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.