← Vulnerability feed

Vulnerability record · CVE-2020-28018 · published 6 May 2021

CVE-2020-28018: Exim SMTP use-after-free in smtp_reset with OpenSSL builds

Exim · Exim

Exim 4 before 4.94.2 contains a use-after-free in smtp_reset that occurs in certain situations common to builds using OpenSSL. Because the flaw is reachable over the network without authentication, it can corrupt memory in the mail server process and potentially lead to code execution.

9.8 CVSS 3.1 Critical EPSS 57% · top 1.0% CWE-416 · Use after free
9.8CVSS 3.1 base score, v2 7.5
57%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
16References
17 Jun 2026Last modified by NVD

Description

Exim 4 before 4.94.2 allows Use After Free in smtp_reset in certain situations that may be common for builds with OpenSSL.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

critical priorityCVSS 9.8 with network reachability, no authentication, and high EPSS make this a critical remote code execution risk for exposed Exim servers.

What it is

Exim 4 before 4.94.2 contains a use-after-free in smtp_reset that occurs in certain situations common to builds using OpenSSL. Because the flaw is reachable over the network without authentication, it can corrupt memory in the mail server process and potentially lead to code execution.

Impact

An unauthenticated remote attacker can trigger memory corruption in the Exim process, which may result in arbitrary code execution or a denial of service on the mail server.

Attack surface

Reached over the network via SMTP against an Exim server built with OpenSSL; the CVSS vector shows no privileges or user interaction required.

Exploitation

Not listed in CISA KEV and no ransomware associations are documented, but EPSS is 0.5675 (99th percentile), indicating high predicted likelihood of exploitation; references are vendor and mailing-list advisories only.

What to do

  • Upgrade Exim to 4.94.2 or later, which fixes this use-after-free.
  • If immediate upgrade is not possible, restrict SMTP access to trusted networks and disable unnecessary exposure of the mail service.
  • Rebuild Exim without OpenSSL where feasible, since the flaw is described as common in OpenSSL builds.
  • Monitor vendor and oss-security advisories for updated guidance and any backported fixes for your distribution.

Detection

  • Monitor Exim logs for crashes, restarts, or abnormal smtp_reset-related errors.
  • Watch for unexpected child process termination or core dumps from the Exim binary.
  • Alert on unusual SMTP session patterns or repeated connection attempts against the mail server.
  • Use host-based memory integrity or crash telemetry to catch signs of use-after-free exploitation.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-28018 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2019-16928Exim heap buffer overflow in string_vformat via long EHLO commandExim 4.92 through 4.92.2 contains a heap-based buffer overflow in string_vformat in string.c triggered by a long EHLO command, allowing remote code e…KEVEPSS 42%analysed9.8CVE-2019-10149Exim MTA improper recipient validation leads to remote command executionExim versions 4.87 through 4.91 fail to properly validate recipient addresses in the deliver_message() function in /src/deliver.c, allowing command i…KEVEPSS 100%analysed9.8CVE-2018-6789Exim SMTP base64d buffer overflow allows remote code executionExim before 4.90.1 contains a buffer overflow in the base64d function of its SMTP listener. A handcrafted message can trigger the overflow, and the f…KEVEPSS 82%analysed9.8CVE-2010-4344Exim SMTP heap buffer overflow enables remote code executionExim before 4.70 has a heap-based buffer overflow in string_vformat in string.c. A remote SMTP session that sends two MAIL commands plus a large mess…KEVEPSS 72%analysed7.8CVE-2010-4345Exim local privilege escalation via alternate config file command injectionExim 4.72 and earlier lets the exim user account specify an alternate configuration file whose directives can contain arbitrary commands, as shown wi…KEVEPSS 18%analysed9.8CVE-2026-45185Exim use after free vulnerabilityExim before 4.99.3, in certain GnuTLS configurations, has a remotely reachable use-after-free in the BDAT body parsing path. It is triggered when a c…EPSS 0.94%9.8CVE-2026-40685Exim out-of-bounds write vulnerabilityIn Exim before 4.99.2, when JSON lookup is enabled, an out-of-bounds heap write can occur when a JSON operator encounters malformed JSON in an untrus…EPSS 0.58%9.8CVE-2025-67896Exim heap-based buffer overflow vulnerabilityExim before 4.99.1, with certain non-default rate-limit configurations, allows a remote heap-based buffer overflow because database records are cast …EPSS 0.47%

Source: NIST National Vulnerability Database (record CVE-2020-28018), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.