CVE-2018-6789 is a heap-based buffer overflow in Exim’s base64 decoding logic, specifically the b64decode/base64d function in base64.c as used by the SMTP listener. The flaw is an off-by-one length calculation error: for malformed base64 input of length 4n+3, Exim allocates a decoded buffer of 3n+1 bytes but can decode and write 3n+2 bytes. This results in a one-byte heap overwrite of adjacent memory. The vulnerable code path is reachable remotely via SMTP authentication mechanisms that invoke base64 decoding, including AUTH PLAIN as described in the supporting content. Researchers showed that with heap grooming using SMTP commands such as EHLO and AUTH, the one-byte overwrite can corrupt adjacent heap metadata and Exim store allocator structures, create overlapping chunks, and ultimately overwrite ACL-related strings such as acl_smtp_rcpt. Because Exim expansion strings can evaluate ${run{...}}, the memory corruption can be turned into pre-authentication remote code execution. The issue affected Exim before 4.90.1; the supporting content states the bug existed since the first commit and therefore affected all earlier versions.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
4 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (2 hidden).
This repository contains a Python 3 proof-of-concept exploit for CVE-2018-6789, a remote code execution vulnerability in Exim mail server versions prior to 4.90.1. The repository consists of two files: a README.md with usage instructions and exim.py, the main exploit script. The exploit connects to a target Exim SMTP service, manipulates heap memory via crafted SMTP commands, and ultimately overwrites internal structures to inject a shell command. The payload is a bash reverse shell that connects back to the attacker's specified host and port. The script is operational and requires the attacker to specify the target host/port and their own host/port for the reverse shell. The attack vector is network-based, targeting the SMTP service. The exploit is not part of a framework and is a standalone operational exploit.
This repository contains a proof-of-concept (PoC) exploit for CVE-2018-6789, a heap buffer overflow vulnerability in Exim mail server. The main file, 'exploit.c', is a C program that connects to a user-specified Exim server and port, and attempts to exploit the vulnerability by sending crafted input. The exploit requires the attacker to provide an 'acl_pointer' value, which is used in the heap manipulation process. Upon successful exploitation, the payload opens a bash shell on the target system, listening on TCP port 9999, which the attacker can then connect to for remote command execution. The repository also includes a README with usage instructions, a minimal Makefile, and a .gitignore. The exploit is network-based, targeting Exim servers accessible over the network, and is a functional PoC rather than a fully weaponized exploit.
This repository is a comprehensive learning and exploitation environment for the Exim RCE vulnerability CVE-2018-6789. It includes Docker and Vagrant configurations to set up a controlled lab with Exim 4.89, debugging tools, and scripts to facilitate exploit development and testing. The main exploit scripts are located in the 'sploits/' directory, with each script implementing a different stage or variant of the heap-based buffer overflow exploit against Exim's SMTP service. The exploits connect to Exim on TCP port 25, manipulate heap memory via crafted SMTP commands (notably AUTH PLAIN with malicious base64 payloads), and ultimately achieve remote code execution by overwriting Exim's ACL configuration in memory to inject and execute arbitrary shell commands. The payload is demonstrated by creating a file on the target system. The environment disables ASLR for reliable exploitation and provides extensive debugging support. The repository targets Exim 4.89 on Linux and is intended for academic and research purposes.
This repository contains a working exploit for CVE-2018-6789, a heap-based buffer overflow vulnerability in Exim 4.89's base64 decoding logic. The exploit is implemented in Python (myexp.py) and leverages the pwn library to interact with a vulnerable Exim SMTP server. The README.md provides a detailed technical analysis of the vulnerability, Exim's memory management, and the exploitation strategy, including heap manipulation and ACL string overwriting to achieve arbitrary command execution. The exploit script connects to the target SMTP server (default 127.0.0.1:25), crafts a series of SMTP commands and payloads to manipulate the heap, and ultimately overwrites the ACL string to inject a ${run{/bin/sh}} directive. When a subsequent SMTP command is processed, Exim executes the injected shell command, granting the attacker code execution on the server. The exploit requires the target to be running a vulnerable Exim configuration with CRAM-MD5 authentication enabled. The repository is well-structured, with a single exploit script, a comprehensive README, and a license file.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
5 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Referenced as a prior Exim vulnerability/exploit involving the store allocator. No further technical details are provided in this content.
An Exim heap-based off-by-one overflow in b64decode/base64.c caused by miscalculating the decoded buffer length, discussed as exploitable to code execution.
An off-by-one heap overflow vulnerability in Exim's base64 decoding logic that can lead to remote code execution in Exim 4.89 and below.
A one-byte heap overflow in Exim's base64 decoding function that can be exploited for pre-authentication remote code execution against Exim SMTP servers.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.