#VU341 Privilege escalation in Exim - CVE-2010-4345
Published: August 22, 2016 / Updated: March 25, 2022
Exim
Exim
Description
The vulnerability allows a local user to escalate privileges on vulnerable system.
The vulnerability exists due to design error in Exim, when allowing local users to load arbitrary configuration file via the "spool_directory" directive. A local user can specify an alternate configuration file with a directive that contains arbitrary commands and execute arbitrary commands on the system with root privileges.
Successful exploitation of this vulnerability will allow a local user to gain root privileges on the system.