Description
Format string vulnerability in daemon.c for Exim 4.x through 4.10, and 3.x through 3.36, allows exim administrative users to execute arbitrary code by modifying the pid_file_path value.
Exploits (1)
exploitdb
WORKING POC
VERIFIED
by Thomas Wana · clocallinux
https://www.exploit-db.com/exploits/22066
References (6)
Scores
EPSS
0.0305
EPSS Percentile
86.7%
Details
Status
published
Products (3)
university_of_cambridge/exim
3.35
university_of_cambridge/exim
3.36
university_of_cambridge/exim
4.10
Published
Dec 23, 2002
Tracked Since
Feb 18, 2026