Vulnerability record · CVE-2020-28018 · published 6 May 2021
CVE-2020-28018: Exim SMTP use-after-free in smtp_reset with OpenSSL builds
Exim · Exim
Exim 4 before 4.94.2 contains a use-after-free in smtp_reset that occurs in certain situations common to builds using OpenSSL. Because the flaw is reachable over the network without authentication, it can corrupt memory in the mail server process and potentially lead to code execution.
Description
Exim 4 before 4.94.2 allows Use After Free in smtp_reset in certain situations that may be common for builds with OpenSSL.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityCVSS 9.8 with network reachability, no authentication, and high EPSS make this a critical remote code execution risk for exposed Exim servers.
What it is
Exim 4 before 4.94.2 contains a use-after-free in smtp_reset that occurs in certain situations common to builds using OpenSSL. Because the flaw is reachable over the network without authentication, it can corrupt memory in the mail server process and potentially lead to code execution.
Impact
An unauthenticated remote attacker can trigger memory corruption in the Exim process, which may result in arbitrary code execution or a denial of service on the mail server.
Attack surface
Reached over the network via SMTP against an Exim server built with OpenSSL; the CVSS vector shows no privileges or user interaction required.
Exploitation
Not listed in CISA KEV and no ransomware associations are documented, but EPSS is 0.5675 (99th percentile), indicating high predicted likelihood of exploitation; references are vendor and mailing-list advisories only.
What to do
- Upgrade Exim to 4.94.2 or later, which fixes this use-after-free.
- If immediate upgrade is not possible, restrict SMTP access to trusted networks and disable unnecessary exposure of the mail service.
- Rebuild Exim without OpenSSL where feasible, since the flaw is described as common in OpenSSL builds.
- Monitor vendor and oss-security advisories for updated guidance and any backported fixes for your distribution.
Detection
- Monitor Exim logs for crashes, restarts, or abnormal smtp_reset-related errors.
- Watch for unexpected child process termination or core dumps from the Exim binary.
- Alert on unusual SMTP session patterns or repeated connection attempts against the mail server.
- Use host-based memory integrity or crash telemetry to catch signs of use-after-free exploitation.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2020-28018 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2020-28018), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.