CISA Known Exploited Vulnerability

CVE-2010-4345

Exim · Exim

Exim Privilege Escalation Vulnerability

Date added
BOD 22-01 due date
CWE CWE-264
Ransomware Unknown

CISA description

Exim allows local users to gain privileges by leveraging the ability of the exim user account to specify an alternate configuration file with a directive that contains arbitrary commands.

Required action

Apply updates per vendor instructions.