Critical Exim bug bypasses security filters on 1.5 million mail servers

Teilen:

Censys warns that over 1.5 million Exim mail transfer agent (MTA) instances are unpatched against a critical vulnerability that lets threat actors bypass security filters.

Tracked as CVE-2024-39929 and patched by Exim developers on Wednesday, the security flaw impacts Exim releases up to and including version 4.97.1.

The vulnerability is due to the incorrect parsing of multiline RFC2231 header filenames, which can let remote attackers deliver malicious executable attachments into end users’ mailboxes by circumventing the $mime_filename extension-blocking protection mechanism.

“If a user were to download or run one of these malicious files, the system could be compromised,” Censys warned, adding that “a PoC is available, but no active exploitation is known yet.”

“As of July 10, 2024, Censys observes 1,567,109 publicly exposed Exim servers running a potentially vulnerable version (4.97.1 or earlier), concentrated mostly in the United States, Russia, and Canada,” the company added.

While email recipients will still need to launch the malicious attachment to be affected, the flaw allows threat actors to bypass security checks based on file extensions. This allows them to deliver risky files that are normally blocked, such as executables, into their targets’ mailboxes.

Admins who cannot immediately upgrade Exim are advised to restrict remote access to their servers from the Internet to block incoming exploitation attempts.

Millions of servers exposed online

MTA servers, such as Exim, are often targeted in attacks because they are almost always accessible via the Internet, making them easy to find potential entry points into a target’s network.

Exim is also the default Debian Linux MTA and is the world’s most popular MTA software, based on a mail server survey from earlier this month.

According to the survey, over 59% of the 409,255 mail servers reachable on the Internet during the survey were running Exim, representing just over 241,000 Exim instances.

Also, per a Shodan search, over 3.3 million Exim servers are currently exposed online, most in the United States, followed by Russia and the Netherlands. Censys found 6,540,044 public-facing mail servers online, 4,830,719 (roughly 74%) running Exim

​The National Security Agency (NSA) revealed in May 2020 that the notorious Russian military hacking group Sandworm has been exploiting a critical CVE-2019-10149 Exim flaw (dubbed The Return of the WIZard) since at least August 2019.

More recently, in October, the Exim devs patched three zero-days disclosed through Trend Micro’s Zero Day Initiative (ZDI), one of them (CVE-2023-42115) exposing millions of Internet-exposed Exim servers to pre-auth RCE attacks.

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
6:12 pm, Juni 12, 2025
Wetter-Symbol 25°C
L: 24° | H: 26°
broken clouds
Luftfeuchtigkeit: 64 %
Druck: 1011 mb
Wind: 8 mph SSW
Windböe: 0 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 75%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 4:43 am
Sonnenuntergang: 9:17 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 10:00 pm
Wetter-Symbol
24° | 26°°C 0 mm 0% 9 mph 67 % 1013 mb 0 mm/h
Tomorrow 10:00 pm
Wetter-Symbol
16° | 27°°C 1 mm 100% 7 mph 94 % 1019 mb 0 mm/h
Sa. Juni 14 10:00 pm
Wetter-Symbol
17° | 23°°C 1 mm 100% 13 mph 96 % 1019 mb 0 mm/h
So. Juni 15 10:00 pm
Wetter-Symbol
13° | 22°°C 0.46 mm 46% 10 mph 84 % 1025 mb 0 mm/h
Mo. Juni 16 10:00 pm
Wetter-Symbol
14° | 25°°C 0 mm 0% 7 mph 86 % 1027 mb 0 mm/h
Today 7:00 pm
Wetter-Symbol
24° | 25°°C 0 mm 0% 9 mph 64 % 1012 mb 0 mm/h
Today 10:00 pm
Wetter-Symbol
20° | 23°°C 0 mm 0% 4 mph 67 % 1013 mb 0 mm/h
Tomorrow 1:00 am
Wetter-Symbol
17° | 20°°C 0 mm 0% 3 mph 75 % 1015 mb 0 mm/h
Tomorrow 4:00 am
Wetter-Symbol
16° | 16°°C 0 mm 0% 3 mph 84 % 1017 mb 0 mm/h
Tomorrow 7:00 am
Wetter-Symbol
18° | 18°°C 0 mm 0% 7 mph 79 % 1018 mb 0 mm/h
Tomorrow 10:00 am
Wetter-Symbol
22° | 22°°C 0 mm 0% 7 mph 60 % 1019 mb 0 mm/h
Tomorrow 1:00 pm
Wetter-Symbol
26° | 26°°C 0 mm 0% 6 mph 41 % 1019 mb 0 mm/h
Tomorrow 4:00 pm
Wetter-Symbol
27° | 27°°C 0 mm 0% 7 mph 40 % 1019 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€93,037.23
-1.56%
Ethereum(ETH)
€2,371.39
-3.60%
Fesseln(USDT)
€0.86
0.00%
XRP(XRP)
€1.94
-3.01%
Solana(SOL)
€136.96
-4.58%
USDC(USDC)
€0.86
0.00%
Dogecoin(DOGE)
€0.162769
-6.70%
Shiba Inu(SHIB)
€0.000011
-5.95%
Pepe(PEPE)
€0.000010
-7.74%
Peanut das Eichhörnchen(PNUT)
€0.236997
-5.02%
Nach oben scrollen