Skip to content
COOEY

FAIL › dossier

Exim

VENDOR

· dossier confidence 20%

Exim, a widely used mail transfer agent, has a history of critical security vulnerabilities, including remote code execution flaws, and has demonstrated challenges in timely patching, as highlighted by the recent exposure of Roundcube webmail servers. This poses a significant risk to organizations relying on Exim for email services and requires careful management and proactive patching.

PROFILE
Categoryemail server softwareWhat they doExim is a mail transfer agent (MTA) used for sending, receiving, and routing email. It is a popular choice for Unix-like operating systems and is known for its flexibility and configurability. Websitehttps://www.exim.org/ ↗
SECURITY POSTURE

Exim has a history of critical vulnerabilities leading to remote code execution, indicating a significant challenge in secure development practices. Patching has been inconsistent, with vulnerabilities remaining unpatched for extended periods, as evidenced by the Roundcube webmail exposure.

Notable failures
  • CVE-2018-6789 (critical RCE)
  • CVE-2010-4344 (critical RCE)
  • CVE-2010-4345 (critical RCE privilege escalation)
  • CVE-2019-16928 (critical RCE)
  • CVE-2019-10149 (critical RCE)
  • Roundcube webmail servers exposed to CVE-2025-49113 despite a patch
Patterns: repeated critical RCE vulnerabilities; delayed patching of known vulnerabilities; vulnerabilities affecting SMTP listeners; local privilege escalation vulnerabilities
FAILURE HISTORY · 8
DATEEVENTSEVSUMMARY
2021-11-03 CVE-2018-6789 critical Exim's base64d function contained a buffer overflow vulnerability exploited in the wild, potentially enabling remote code execution.
2021-11-03 CVE-2018-6789 critical Exim's base64d function contained a buffer overflow vulnerability exploited in the wild, potentially enabling remote code execution.
2022-03-25 CVE-2010-4344 high Exim's heap-based buffer overflow in string_vformat allowed remote attackers to execute arbitrary code via an SMTP session.
2022-03-25 CVE-2010-4344 high Exim's heap-based buffer overflow in string_vformat allowed remote attackers to execute arbitrary code via an SMTP session.
2022-03-25 CVE-2010-4345 high Local users can escalate privileges in Exim by executing arbitrary commands via alternate configuration files.
2022-03-25 CVE-2010-4345 high Local users can escalate privileges in Exim by executing arbitrary commands via alternate configuration files.
2022-03-03 CVE-2019-16928 high Exim Internet Mailer's unpatched out-of-bounds write vulnerability allowed remote code execution and was actively exploited in the wild.
2022-01-10 CVE-2019-10149 high Exim MTA's improper input validation allowed remote command execution via recipient address manipulation.
SENTIMENT · TRUSTED SOURCES
synthesissevere-fallout-0.70
cooey ↗severe-fallout-0.70
"…"
Open questions: What is Exim's current patching cadence? · What is the extent of Exim's usage within our environment? · Are there alternative MTAs with a better security track record?
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-20 04:42:26.471516+00:00