#VU341 Privilege escalation in Exim - CVE-2010-4345

 

#VU341 Privilege escalation in Exim - CVE-2010-4345

Published: August 22, 2016 / Updated: March 25, 2022


Vulnerability identifier: #VU341
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:L/SI:L/SA:L/E:A/U:Clear
CVE-ID: CVE-2010-4345
CWE-ID: CWE-78
Exploitation vector: Local access
Exploit availability: The vulnerability is being exploited in the wild
Vulnerable software:
Exim
Software vendor:
Exim

Description

The vulnerability allows a local user to escalate privileges on vulnerable system.

The vulnerability exists due to design error in Exim, when allowing local users to load arbitrary configuration file via the "spool_directory" directive. A local user can specify an alternate configuration file with a directive that contains arbitrary commands and execute arbitrary commands on the system with root privileges.

Successful exploitation of this vulnerability will allow a local user to gain root privileges on the system.


Remediation

Update to version 4.73.

External links