World's biggest email server hit with security flaw

(Image credit: Panumas Nikhomkhai / Pexels)

A security bug has been discovered in millions of Exim servers that could be exploited to give potential attackers the ability to run malicious code with root privileges.

The Exim team revealed in a recent advisory that all of its servers running version 4.92.1 or lower are vulnerable though the company has released version 4.92.2 to address the vulnerability.

If you're unfamiliar with Exim, the software is a mail transfer agent (MTA) that runs in the background of email servers. In addition to helping send and receive messages, email servers also serve as relays for other user's emails and MTA helps handle this.

Exim is currently the most popular MTA today and a big reason for this stems from the fact that the software is bundled with many popular Linux distros including Debian and Red Hat.

Exim vulnerability

If an Exim server is configured to accept incoming TLS connections, an attacker can send a malicious backslash-null sequence attached to the ending of an SNI packet and this would allow them to run malicious code with root privileges.

A security researcher named Zerons first discovered the issue and reported it to Exim in early July. Since then, the company has secretly worked to patch the vulnerability because of its seriousness and how many of its servers could be vulnerable to a potential attack.

Luckily the vulnerability can be mitigated by disabling TLS support on all Exim servers though this fix does expose email traffic in cleartext which makes it vulnerable to being intercepted as well as to sniffing attacks. However, if you own an Exim server and live in the EU, this fix is not recommended as it could lead to data leaks and fines under GDPR.

Exim installations do not have TLS support enabled by default though Exim instances that are included with Linux distros do. Additionally, Exim instances that ship with cPanel also support TLS by default but cPanel has already integrated the Exim patch into an update they've begun to roll out to customers.

If you're unsure of the TLS status of your Exim servers, it is highly recommended that you install the Exim patch as this is the only way to fully prevent the vulnerability from being exploited on your server.

Via ZDNet

TOPICS
Anthony Spadafora

After working with the TechRadar Pro team for the last several years, Anthony is now the security and networking editor at Tom’s Guide where he covers everything from data breaches and ransomware gangs to the best way to cover your whole home or business with Wi-Fi. When not writing, you can find him tinkering with PCs and game consoles, managing cables and upgrading his smart home. 

Latest in Security
Hacker silhouette working on a laptop with North Korean flag on the background
North Korea unveils new military unit targeting AI attacks
An image of network security icons for a network encircling a digital blue earth.
US government warns agencies to make sure their backups are safe from NAKIVO security issue
Laptop computer displaying logo of WordPress, a free and open-source content management system (CMS)
This top WordPress plugin could be hiding a worrying security flaw, so be on your guard
Computer Hacked, System Error, Virus, Cyber attack, Malware Concept. Danger Symbol
Veeam urges users to patch security issues which could allow backup hacks
UK Prime Minister Sir Kier Starmer
The UK releases timeline for migration to post-quantum cryptography
Representational image depecting cybersecurity protection
Cisco smart licensing system sees critical security flaws exploited
Latest in News
Ray-Ban Meta Smart Glasses
Samsung's rumored smart specs may be launching before the end of 2025
Apple iPhone 16 Review
The latest iPhone 18 leak hints at a major chipset upgrade for all four models
Quordle on a smartphone held in a hand
Quordle hints and answers for Monday, March 24 (game #1155)
NYT Strands homescreen on a mobile phone screen, on a light blue background
NYT Strands hints and answers for Monday, March 24 (game #386)
NYT Connections homescreen on a phone, on a purple background
NYT Connections hints and answers for Monday, March 24 (game #652)
Quordle on a smartphone held in a hand
Quordle hints and answers for Sunday, March 23 (game #1154)