Vulnerability record · CVE-2018-6789 · published 8 February 2018
CVE-2018-6789: Exim SMTP base64d buffer overflow allows remote code execution
Exim · Exim
Exim before 4.90.1 contains a buffer overflow in the base64d function of its SMTP listener. A handcrafted message can trigger the overflow, and the flaw can be used to execute code remotely. Because Exim is a widely deployed mail transfer agent, an unauthenticated network flaw in its SMTP path is serious.
Description
An issue was discovered in the base64d function in the SMTP listener in Exim before 4.90.1. By sending a handcrafted message, a buffer overflow may happen. This can be used to execute code remotely.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8, unauthenticated network reachability, confirmed KEV exploitation with ransomware use, and a very high EPSS probability make this an urgent patch.
What it is
Exim before 4.90.1 contains a buffer overflow in the base64d function of its SMTP listener. A handcrafted message can trigger the overflow, and the flaw can be used to execute code remotely. Because Exim is a widely deployed mail transfer agent, an unauthenticated network flaw in its SMTP path is serious.
Impact
An attacker can execute arbitrary code on the mail server, likely with the privileges of the Exim process. That gives full control of the host's mail handling and a foothold for further compromise.
Attack surface
Reachable over the network through the SMTP listener; the CVSS vector shows no privileges required and no user interaction. The description does not specify whether a valid recipient or session state is needed before the crafted message is processed.
Exploitation
CISA KEV lists it as exploited, with known ransomware campaign use, and EPSS gives a 30-day probability of 0.82137 (99.6th percentile). Multiple references are tagged Exploit, including public write-ups and Exploit-DB entries.
What to do
- Upgrade Exim to 4.90.1 or later, or apply the vendor patch commit cf3cd306062a08969c41a1cdd32c6855f1abecf1.
- Apply the Debian DSA-4110 or Ubuntu USN-3565-1 updates for distribution-packaged Exim.
- If immediate patching is not possible, restrict SMTP exposure to trusted networks and disable or limit the base64d code path where feasible.
- Monitor for and block known exploit traffic against the SMTP listener.
- Verify no unauthorized code or persistence was placed on hosts that ran vulnerable Exim.
Detection
- Inspect SMTP logs for malformed or unusually long base64-encoded message content sent to the listener.
- Hunt for unexpected child processes, shells, or outbound connections spawned by the Exim service account.
- Check for Exim crashes or restarts that correlate with inbound SMTP traffic.
- Use file integrity monitoring on Exim binaries and configuration to catch post-exploitation changes.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2018-6789 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "Exim Buffer Overflow Vulnerability". CISA reports known use in ransomware campaigns. Required action: Apply updates per vendor instructions. Federal deadline 3 May 2022.
Affected products
3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2018-6789 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2018-6789), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.