Three critical vulnerabilities in Exim that allow remote code execution on the server
The Zero Day Initiative (ZDI) has disclosed information about unpatched (0-day) vulnerabilities (CVE-2023-42115, CVE-2023-42116, CVE-2023-42117) in the Exim mail server that allow the remote execution of arbitrary code on the server with the privileges of the process that accepts connections on port 25. No authentication is required to carry out the attack. The first vulnerability (CVE-2023-42115) is caused by an error in the SMTP service and is related to the lack of proper data verification […]
