Skip to content
COOEY

EXPOSURES › CVE-2010-4345

CVE-2010-4345

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2022-03-25 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2010-4345 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 78/100 rceexploited-in-wildprivilege-escalationunpatched

Local users can escalate privileges in Exim by executing arbitrary commands via alternate configuration files.

This privilege escalation flaw allows local attackers to run arbitrary commands, bypassing intended access controls. DIB organizations must patch Exim immediately and restrict local user privileges to prevent lateral movement and compliance violations. The vulnerability is actively exploited in the wild, indicating a high risk of compromise.

Shame score — A known privilege escalation flaw in a widely deployed mail server was actively exploited in the wild, demonstrating severe negligence in patch management and security hygiene.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Exim allows local users to gain privileges by leveraging the ability of the exim user account to specify an alternate configuration file with a directive that contains arbitrary commands.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.