Qualys researchers uncover 21 bugs in Exim mail servers
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2020-28017 | Exim 4 before 4.94.2 allows Integer Overflow to Buffer Overflow in receive_add_recipient via an e-mail message with fifty million recipients. Exim 4 before 4.94.2 allows Integer Overflow to Buffer Overflow in receive_add_recipient via an e-mail message with fifty million recipients. NOTE: remote exploitation may be difficult because of resource consumption. NVD description · AI analysis pending | 9.8 | 37% |
| — |
Full article580 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
It's the kind of access the NSA has described as a "dream" for Russian hackers.
Researchers have found 21 unique vulnerabilities in Exim, a popular mail transfer agent, some of which would allow hackers to run full remote unauthenticated code execution against targets, the Qualys Research Team announced Tuesday.
If used properly, attackers could execute commands to install programs, manipulate data, create new accounts or change settings on the mail servers, according to the research. CVE-2020-28017, one of the vulnerabilities, dates as far back as 2004, according to the findings. Qualys and Exim recommend users apply the patches immediately.
The Exim Mail Transfer Agent (MTA) vulnerabilities, which Qualys is referring to collectively as 21Nails, affect all versions before Exim-4.94.1.
Ten of the flaws can be executed to gain root privileges, while 11 of them can be used to exploit victim systems locally. Hackers could link several of the vulnerabilities together in an attack to run full remote unauthenticated code execution against vulnerable mail servers, Qualys said.
Exim MTA software has not had smooth sailing over the last year. Hackers working for Russia’s military intelligence agency, a group also known as Sandworm, used Exim vulnerabilities last year in order to disable victims’ network security settings and execute commands and code remotely, according to the National Security Agency.
The NSA previously said using the mail transfer agent software vulnerability was “any attacker’s dream access.”
Almost exactly one year to date, Qualys shares the NSA’s concerns that Exim could provide hackers an attractive target to go after target lists.
“Exim Mail Servers are used so widely and handle such a large volume of the internet’s traffic that they are often a key target for hackers,” said Bharat Jogi, senior manager of vulnerability and threat research at Qualys. “It’s imperative that users apply patches immediately.”
The Qualys Research Team began exploring Exim for vulnerabilities in October of last year. Immediately after they found the flaws, Exim started developing patches, according to Qualys, which says it also worked on developing the fixes. Exim noted in an email to users that the updates took “more time than usual” to work on the reported issues due to “internal reasons,” but thanked Qualys for having reported the issues and the team’s work on patches.
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
Jail time for Maine child in 764 marks turning point in federal law enforcement
Technology
Threats
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/qualys-cybersecurity-email-bugs/