Serious vulnerabilities in the widely-used Exim message transfer agent (MTA) software have put hundreds of thousands of systems at risk of remote code execution (RCE).
Urgent Patches Required for Exim Mail Servers Worldwide Exim plays a crucial role in handling email traffic and often operates on internet-exposed systems, making it susceptible to exploitation when vulnerabilities are present.
As of October 1, a regular Securityspace survey identified over 300,000 Exim servers accessible from the internet.
One of the critical vulnerabilities, CVE-2023-42115, resides in Exim’s simple mail transfer protocol (SMTP) service, which listens on TCP port 25. This flaw allows attackers to overwrite data beyond the boundaries of a buffer. Exploiting it provides an unauthenticated remote attacker with the capability to execute code within the context of the SMTP service, earning it a CVSS score of 9.8.
This vulnerability was disclosed through the Zero Day Initiative as one of six zero-day vulnerabilities reported through the program.
Additionally, there are two high-rated bugs with a CVSS score of 8.1:
- CVE-2023-42116: A buffer overflow in Exim’s SMTP challenge component.
- CVE-2023-42117: A memory corruption bug in the SMTP service, which could also enable an attacker to execute code remotely.
According to information shared on the oss-sec mailing list, patches have been made available for three of these vulnerabilities and will soon be applied by Exim’s maintainers. More information is needed to address the remaining issues.
Exim has required urgent patches twice in 2019, in June and October, and in 2020, the US National Security Agency (NSA) warned that the MTA was being targeted by the Russian hacking operation known as Sandworm.

