Back

HIGH KEV

exim: privilege escalation

Published Dec 14, 2010 ·Due Apr 15, 2022

Description

Exim 4.72 and earlier allows local users to gain privileges by leveraging the ability of the exim user account to specify an alternate configuration file with a directive that contains arbitrary commands, as demonstrated by the spool_directory directive.

Affected products

Remediation

No remediation recorded yet.

Metrics

References (33)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Dec 14, 2010
Updated Oct 22, 2025
Reserved Nov 30, 2010
CISA Vulnrichment
Updated Feb 7, 2025
NVD
Status Analyzed
Modified Jun 16, 2026
Red Hat
Severity Moderate
Public date Dec 7, 2010