Skip to content
COOEY

EXPOSURES › CVE-2010-4344

CVE-2010-4344

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-03-25 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2010-4344 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 78/100 rceexploited-in-wildunpatched

Exim's heap-based buffer overflow in string_vformat allowed remote attackers to execute arbitrary code via an SMTP session.

A heap-based buffer overflow in Exim's string_vformat function enabled remote code execution through an SMTP session, marking it as an actively exploited vulnerability. DIB organizations must ensure Exim is patched to prevent attackers from compromising mail servers and gaining footholds for lateral movement or data exfiltration. This failure highlights the risk of relying on unpatched software, especially when the vulnerability is known and actively exploited in the wild.

Shame score — The vulnerability was actively exploited in the wild (KEV) and allowed remote code execution, indicating a severe and avoidable failure to patch known, critical flaws.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Heap-based buffer overflow in the string_vformat function in string.c in Exim before 4.70 allows remote attackers to execute arbitrary code via an SMTP session.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.