A vulnerability in clamav-milter, part of ClamAV before version 0.91.2, allows remote attackers to execute arbitrary commands on the system. When clamav-milter is run in black hole mode, it improperly handles shell metacharacters in the recipient field of sendmail, passing them unsanitized to a popen call. This allows attackers to inject and execute arbitrary shell commands with the privileges of the clamav-milter process.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
3 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (2 hidden).
This repository is a small standalone Python exploit repo containing a GPL license, a README, and one executable script: sendmail_clamav_exploit.py. The script is the clear entry point and implements a remote command-injection exploit for CVE-2007-4560 affecting Sendmail deployments using vulnerable ClamAV-Milter versions prior to 0.91.2. The exploit works over the network by opening a raw TCP connection to the target's SMTP service on port 25, performing a minimal SMTP dialogue (EHLO, MAIL FROM), and then sending two crafted RCPT TO commands. These RCPT TO values abuse shell metacharacter injection in clamav-milter processing. The first injected command appends an inetd service line to /etc/inetd.conf that exposes /bin/sh as a root bind shell on TCP/1001. The second injected command restarts inetd via /etc/init.d/inetd restart so the new service becomes active immediately. Capabilities are straightforward but high impact: unauthenticated remote exploitation leading to root-level command execution and persistent-ish backdoor access through a bind shell. The payload is hardcoded rather than operator-customizable, which supports an OPERATIONAL maturity assessment rather than WEAPONIZED. It is not a scanner or detector; it is an actual exploit delivery script. Repository structure is minimal and purpose-built: README.md documents the vulnerability, usage, tested versions, and post-exploitation steps; sendmail_clamav_exploit.py contains all exploit logic using only Python's standard socket and sys modules. No framework affiliation is evident. The exploit assumes a Linux-like target using inetd, with writable /etc/inetd.conf and a restartable /etc/init.d/inetd service path, so it is tailored to older Unix/Linux mail server environments rather than being broadly portable.
This repository contains a Python exploit for CVE-2007-4560, targeting Sendmail servers with ClamAV-Milter versions less than 0.91.2. The exploit leverages a command injection vulnerability in the handling of SMTP RCPT TO headers, allowing remote attackers to execute arbitrary commands as root. The main script, 'sendmail_clamav_exploit.py', connects to the target's SMTP port (25), injects a payload that appends a root shell service to /etc/inetd.conf, and restarts the inetd service. This results in a bind shell being available on TCP port 1001, which the attacker can connect to for root access. The repository is well-structured, with a single exploit script, a README providing background and usage instructions, and a license file. No external dependencies are required beyond Python 3. The exploit is operational and provides a working root shell if the target is vulnerable.
This repository contains a single Metasploit exploit module targeting a remote code execution vulnerability in ClamAV's 'clamav-milter' (Sendmail mail filter) prior to version 0.92.2, specifically when black hole mode is enabled. The exploit abuses an insecure popen call, allowing an attacker to execute arbitrary shell commands on the target system by sending a specially crafted SMTP message. The payload is injected via the 'From:' header and executed by manipulating the RCPT TO address to trigger execution of a temporary file created by clamav-milter. The exploit supports various command payloads (bash, perl, ruby, telnet, etc.) and is operational, requiring the attacker to have SMTP access to the target. The main fingerprintable endpoint is the temporary directory and message file used by clamav-milter, and the attack vector is network-based via SMTP. The repository is structured as a single Ruby file within the Metasploit framework.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.