EXPOSURES › CVE-2010-4344
CVE-2010-4344
HIGH ⌖ ON CISA KEV · EXPLOITEDExim's heap-based buffer overflow in string_vformat allowed remote attackers to execute arbitrary code via an SMTP session.
A heap-based buffer overflow in Exim's string_vformat function enabled remote code execution through an SMTP session, marking it as an actively exploited vulnerability. DIB organizations must ensure Exim is patched to prevent attackers from compromising mail servers and gaining footholds for lateral movement or data exfiltration. This failure highlights the risk of relying on unpatched software, especially when the vulnerability is known and actively exploited in the wild.
Shame score — The vulnerability was actively exploited in the wild (KEV) and allowed remote code execution, indicating a severe and avoidable failure to patch known, critical flaws.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Heap-based buffer overflow in the string_vformat function in string.c in Exim before 4.70 allows remote attackers to execute arbitrary code via an SMTP session.