CVE-2002-1381

Exim 3.x-3.36 and 4.x-4.10 - Authenticated Remote Code Execution via pid_file_path Format String

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2002-1381. PoCs published by Thomas Wana.

AI-analyzed exploit summary This exploit leverages a format string vulnerability in Exim's daemon_go() function to achieve local privilege escalation. It calculates stack pops and overwrites the GOT entry for fopen() to redirect execution to shellcode.

Description

Format string vulnerability in daemon.c for Exim 4.x through 4.10, and 3.x through 3.36, allows exim administrative users to execute arbitrary code by modifying the pid_file_path value.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Thomas Wana · clocallinux
https://www.exploit-db.com/exploits/22066

This exploit leverages a format string vulnerability in Exim's daemon_go() function to achieve local privilege escalation. It calculates stack pops and overwrites the GOT entry for fopen() to redirect execution to shellcode.

Classification
Working Poc 95%
Attack Type
Lpe
Complexity
Complex
Reliability
Reliable
Target: Exim 4.10 (and possibly others)
Auth required
Prerequisites: Exim compiled with 'exim-admin-user' defined · Local access to the system · Exim binary path
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (6)

Core 6
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/10761
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/6314
Mailing List mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=103903403527788&w=2
Mailing List vendor-advisory x_refsource_gentoo
http://marc.info/?l=bugtraq&m=104006219018664&w=2
Exploit, Patch, Vendor Advisory x_refsource_confirm
http://groups.yahoo.com/group/exim-users/message/42358
Various Sources mailing-list x_refsource_mlist
http://www.exim.org/pipermail/exim-users/Week-of-Mon-20021202/046978.html

Scores

EPSS 0.0230
EPSS Percentile 81.1%

Details

Status published
Products (3)
university_of_cambridge/exim 3.35
university_of_cambridge/exim 3.36
university_of_cambridge/exim 4.10
Published Dec 23, 2002
Tracked Since Feb 18, 2026