5 May 2021

Millions Exim email servers impacted by dangerous flaws


Millions Exim email servers impacted by dangerous flaws

Millions of unpatched Exim email servers are potentially vulnerable to a set of bugs collectively called ‘21 Nails’ that could expose servers to cyberattacks. The vulnerabilities discovered by researchers at Qualys allow unauthenticated remote hackers to execute arbitrary code and gain root privilege on mail servers with default or common configurations.

According to Qualys, the popular mail transfer agent Exim contains 21 vulnerabilities, ten of which can be exploited remotely and other 11 issues are local flaws (the full list can be found here).

‘21 Nails’ flaws impact all versions of Exim before 4.94.2. “Some of the vulnerabilities can be chained together to obtain a full remote unauthenticated code execution and gain root privileges on the Exim Server,” Qualys said in a blog post.

The researchers noted that discovered vulnerabilities affect all Exim versions "going back all the way to 2004," meaning that most vulnerabilities have been present for 17 years.

According to a Shodan search, there are nearly four million known exposed Exim servers. A SecuritySpace survey from March estimated that 60% of visible mail servers use Exim.

Developers behind Exim have released a security update exim-4.94.2 that contains all changes on the exim-4.94+fixes branch and security fixes. Users are strongly advised to update their Exim instances as soon as possible.


Back to the list

Latest Posts

Cyber Security Week in Review: April 19, 2024

Cyber Security Week in Review: April 19, 2024

In brief: the LabHost PhaaS platform shut down, Russian military hackers attacked critical infrastructure in the US and Europe, and more.
19 April 2024
Ukrainian military personnel targeted via messaging apps and dating sites

Ukrainian military personnel targeted via messaging apps and dating sites

The threat actor employs a range of software in their malicious activities, including both commercial programs and  open-source tools.
18 April 2024
Russian military hackers targeted US water utilities and hydroelectric facilities in Europe

Russian military hackers targeted US water utilities and hydroelectric facilities in Europe

This marks the first time Russian nation-state hackers have posed a direct threat to critical infrastructure in Western countries.
18 April 2024