EXPOSURES › CVE-2019-16928
CVE-2019-16928
HIGH ⌖ ON CISA KEV · EXPLOITEDExim Internet Mailer's unpatched out-of-bounds write vulnerability allowed remote code execution and was actively exploited in the wild.
Exim's CVE-2019-16928 was an out-of-bounds write flaw enabling remote code execution, which remained unpatched long enough to be added to CISA's KEV catalog. DIB organizations must ensure mail servers are patched against known RCE vulnerabilities to prevent attackers from compromising email infrastructure and exfiltrating sensitive data. The failure highlights the risk of relying on unpatched software and the necessity of continuous vulnerability management.
Shame score — The vulnerability was known, unpatched, and actively exploited in the wild, demonstrating negligence in maintaining secure email infrastructure.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Exim contains an out-of-bounds write vulnerability which can allow for remote code execution.