CVE-2018-6789

CRITICAL KEV RANSOMWARE

Exim < 4.90.1 - Buffer Overflow

Title source: rule

Description

An issue was discovered in the base64d function in the SMTP listener in Exim before 4.90.1. By sending a handcrafted message, a buffer overflow may happen. This can be used to execute code remotely.

Exploits (7)

exploitdb WORKING POC
by hackk.gr · pythonremotelinux
https://www.exploit-db.com/exploits/45671
exploitdb WORKING POC
by straight_blast · pythonremotelinux
https://www.exploit-db.com/exploits/44571
nomisec WORKING POC 10 stars
by martinclauss · dos
https://github.com/martinclauss/exim-rce-cve-2018-6789
nomisec WORKING POC 9 stars
by synacktiv · remote
https://github.com/synacktiv/Exim-CVE-2018-6789
nomisec WORKING POC 3 stars
by beraphin · remote
https://github.com/beraphin/CVE-2018-6789
nomisec WORKING POC 2 stars
by thistehneisen · remote
https://github.com/thistehneisen/CVE-2018-6789-Python3
nomisec WORKING POC
by c0llision · local
https://github.com/c0llision/exim-vuln-poc

Scores

CVSS v3 9.8
EPSS 0.8644
EPSS Percentile 99.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CISA KEV 2021-11-03
VulnCheck KEV 2020-02-25
InTheWild.io 2021-07-23
ENISA EUVD EUVD-2018-18536
Ransomware Use Confirmed
CWE
CWE-120
Status published
Products (7)
canonical/ubuntu_linux 14.04
canonical/ubuntu_linux 16.04
canonical/ubuntu_linux 17.10
debian/debian_linux 7.0
debian/debian_linux 8.0
debian/debian_linux 9.0
exim/exim < 4.90.1
Published Feb 08, 2018
KEV Added Nov 03, 2021
Tracked Since Feb 18, 2026