CVE-2019-10149

CRITICAL KEV

Exim 4.87 - 4.91 Local Privilege Escalation

Title source: metasploit

Description

A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message() function in /src/deliver.c may lead to remote command execution.

Exploits (24)

exploitdb WORKING POC VERIFIED
by Metasploit · rubylocallinux
https://www.exploit-db.com/exploits/47307
exploitdb WORKING POC VERIFIED
by Marco Ivaldi · bashlocallinux
https://www.exploit-db.com/exploits/46996
exploitdb WRITEUP
by Qualys Corporation · textremotelinux
https://www.exploit-db.com/exploits/46974
nomisec TROJAN 22 stars
by bananaphones · poc
https://github.com/bananaphones/exim-rce-quickfix
nomisec WORKING POC 18 stars
by Diefunction · remote
https://github.com/Diefunction/CVE-2019-10149
nomisec WORKING POC 14 stars
by MNEMO-CERT · local
https://github.com/MNEMO-CERT/PoC--CVE-2019-10149_Exim
nomisec WORKING POC 13 stars
by cowbe0x004 · poc
https://github.com/cowbe0x004/eximrce-CVE-2019-10149
nomisec WORKING POC 9 stars
by AzizMea · local
https://github.com/AzizMea/CVE-2019-10149-privilege-escalation
nomisec WORKING POC 5 stars
by darsigovrustam · local
https://github.com/darsigovrustam/CVE-2019-10149
nomisec WORKING POC 4 stars
by Chris-dev1 · local
https://github.com/Chris-dev1/exim.exp
nomisec WRITEUP 3 stars
by cloudflare · poc
https://github.com/cloudflare/exim-cve-2019-10149-data
nomisec SCANNER 3 stars
by Brets0150 · poc
https://github.com/Brets0150/StickyExim
nomisec WORKING POC 1 stars
by Stick-U235 · local
https://github.com/Stick-U235/CVE-2019-10149-Exploit
nomisec WORKING POC 1 stars
by aishee · poc
https://github.com/aishee/CVE-2019-10149-quick
nomisec WORKING POC
by CybersRMUTL · remote
https://github.com/CybersRMUTL/CVE-2019-10149-Exim4-RCE
nomisec WORKING POC
by VoyagerOnne · remote
https://github.com/VoyagerOnne/Exim-CVE-2019-10149
nomisec WORKING POC
by uyerr · remote
https://github.com/uyerr/PoC_CVE-2019-10149--rce
nomisec STUB
by qlusec · local
https://github.com/qlusec/CVE-2019-10149
nomisec WORKING POC
by hyim0810 · remote
https://github.com/hyim0810/CVE-2019-10149
nomisec STUB
by rahmadsandy · poc
https://github.com/rahmadsandy/EXIM-4.87-CVE-2019-10149
nomisec STUB
by Dilshan-Eranda · poc
https://github.com/Dilshan-Eranda/CVE-2019-10149
vulncheck_xdb WORKING POC
local
https://github.com/0xdea/exploits
metasploit WORKING POC EXCELLENT
by Qualys, Dennis Herrmann, Marco Ivaldi, Guillaume André · rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/local/exim4_deliver_message_priv_esc.rb

References (21)

... and 1 more

Scores

CVSS v3 9.8
EPSS 0.9392
EPSS Percentile 99.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CISA KEV 2022-01-10
VulnCheck KEV 2019-12-27
InTheWild.io 2019-06-09
ENISA EUVD EUVD-2019-2187
CWE
CWE-78
Status published
Products (4)
canonical/ubuntu_linux 18.04
canonical/ubuntu_linux 18.10
debian/debian_linux 9.0
exim/exim 4.87 - 4.91
Published Jun 05, 2019
KEV Added Jan 10, 2022
Tracked Since Feb 18, 2026