Multiple flaws in the Exim mail transfer agent include CVE-2023-42115, a critical unauthenticated remote-code-execution vulnerability rated CVSS 9.8. The out-of-bounds write affects Exim's SMTP service when the EXTERNAL authentication scheme is configured and available, potentially enabling an unauthenticated remote attacker to execute code as the Exim service account.
Exim versions 4.96.1 and 4.97 address CVE-2023-42115 and the related CVE-2023-42114 and CVE-2023-42116 vulnerabilities. Organizations should upgrade promptly; where immediate patching is not possible, they should disable exposed authentication features and limit remote SMTP access. Other disclosed issues depend on configurations such as SPA/NTLM authentication, an untrusted Proxy Protocol proxy, SPF ACL use, or reliance on an untrusted DNS resolver.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
Exim versions 4.96.1 and 4.97 fixed CVE-2023-42114, CVE-2023-42115, and CVE-2023-42116. At the time described, CVE-2023-42117 and CVE-2023-42118 had no available fixes and were assumed to affect all Exim versions.
The Zero Day Initiative publicly disclosed multiple Exim MTA vulnerabilities, including critical unauthenticated RCE flaw CVE-2023-42115. The issue is an out-of-bounds write reachable when EXTERNAL authentication is configured and can allow code execution as the Exim service account.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.