CVE-2023-42117

CRITICAL LAB

Exim < 4.96.2 - Remote Code Execution

Title source: rule

Description

Exim Improper Neutralization of Special Elements Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Exim. Authentication is not required to exploit this vulnerability. The specific flaw exists within the smtp service, which listens on TCP port 25 by default. The issue results from the lack of proper validation of user-supplied data, which can result in a memory corruption condition. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-17554.

Exploits (1)

github WORKING POC 1 stars
by exploitintel · pythonpoc
https://github.com/exploitintel/eip-pocs-and-cves/tree/main/CVE-2023-42117

Scores

CVSS v3 9.8
EPSS 0.0735
EPSS Percentile 91.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Lab Environment

vulnerable
docker pull ghcr.io/exploitintel/cve-2023-42117-vulnerable:latest
All Labs GitHub

Classification

CWE
CWE-138
Status published

Affected Products (1)

exim/exim < 4.96.2

Timeline

Published May 03, 2024
Tracked Since Feb 18, 2026