FAIL › dossier
Exim
VENDOR· dossier confidence 20%
Exim, a widely used mail transfer agent, has a history of critical security vulnerabilities, including remote code execution flaws, and has demonstrated challenges in timely patching, as highlighted by the recent exposure of Roundcube webmail servers. This poses a significant risk to organizations relying on Exim for email services and requires careful management and proactive patching.
PROFILE
Categoryemail server softwareWhat they doExim is a mail transfer agent (MTA) used for sending, receiving, and routing email. It is a popular choice for Unix-like operating systems and is known for its flexibility and configurability.
Websitehttps://www.exim.org/ ↗
SECURITY POSTURE
Exim has a history of critical vulnerabilities leading to remote code execution, indicating a significant challenge in secure development practices. Patching has been inconsistent, with vulnerabilities remaining unpatched for extended periods, as evidenced by the Roundcube webmail exposure.
Notable failures
- CVE-2018-6789 (critical RCE)
- CVE-2010-4344 (critical RCE)
- CVE-2010-4345 (critical RCE privilege escalation)
- CVE-2019-16928 (critical RCE)
- CVE-2019-10149 (critical RCE)
- Roundcube webmail servers exposed to CVE-2025-49113 despite a patch
Patterns: repeated critical RCE vulnerabilities; delayed patching of known vulnerabilities; vulnerabilities affecting SMTP listeners; local privilege escalation vulnerabilities
FAILURE HISTORY · 8
| DATE | EVENT | SEV | SUMMARY |
|---|---|---|---|
| 2021-11-03 | CVE-2018-6789 | critical | Exim's base64d function contained a buffer overflow vulnerability exploited in the wild, potentially enabling remote code execution. |
| 2021-11-03 | CVE-2018-6789 | critical | Exim's base64d function contained a buffer overflow vulnerability exploited in the wild, potentially enabling remote code execution. |
| 2022-03-25 | CVE-2010-4344 | high | Exim's heap-based buffer overflow in string_vformat allowed remote attackers to execute arbitrary code via an SMTP session. |
| 2022-03-25 | CVE-2010-4344 | high | Exim's heap-based buffer overflow in string_vformat allowed remote attackers to execute arbitrary code via an SMTP session. |
| 2022-03-25 | CVE-2010-4345 | high | Local users can escalate privileges in Exim by executing arbitrary commands via alternate configuration files. |
| 2022-03-25 | CVE-2010-4345 | high | Local users can escalate privileges in Exim by executing arbitrary commands via alternate configuration files. |
| 2022-03-03 | CVE-2019-16928 | high | Exim Internet Mailer's unpatched out-of-bounds write vulnerability allowed remote code execution and was actively exploited in the wild. |
| 2022-01-10 | CVE-2019-10149 | high | Exim MTA's improper input validation allowed remote command execution via recipient address manipulation. |
SENTIMENT · TRUSTED SOURCES
synthesissevere-fallout-0.70
…
DOSSIER SOURCES
- Critical Vulnerabilities Management (CVM) Risk Vector: Core Overview ... · help.bitsighttech.com
- Over 84,000 Roundcube Webmail Servers Exposed to Actively Exploited ... · dailysecurityreview.com
- CISA KEV Timelines and OT Patch Cadence: A Practitioner's Guide - MES ... · www.mesengineer.com
Open questions: What is Exim's current patching cadence? · What is the extent of Exim's usage within our environment? · Are there alternative MTAs with a better security track record?
DOSSIER · dex-RAG synthesis · grounded in our own collection + trusted sourcesbuilt 2026-07-20 04:42:26.471516+00:00