CVE-2019-10149

A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message() function in /src/deliver.c may lead to remote command execution.

  • Published Jun 5, 2019
  • CVSS 9.8 critical
  • 100.0% chance of exploitation in the next 30 days (EPSS)
  • In CISA's Known Exploited Vulnerabilities catalog
  • A Metasploit module exploits it
  • A fix is available

Affected software

CVE-2019-10149 at the National Vulnerability Database