Millions of email servers could be at risk from Exim security flaw

Best email services: image of email with one unread message alert
(Image credit: Future)

Researchers have discovered a critical vulnerability in the Exim mail transfer agent, which puts roughly 1.5 million email servers at risk of delivering malware to their users. 

Exim is a mail transfer agent (MTA) used on Unix-like operating systems, responsible for routing, delivering, and receiving email messages. As a flexible, and highly configurable agent, Exim is a vastly popular choice among IT teams. 

The researchers from security firm Censys found a vulnerability that hackers can use to bypass protections that usually prevent email messages from delivering attachments that can install apps or run code. The vulnerability is tracked as CVE-2024-39929, and carries a severity rating of 9.1/10 (critical).

Not (yet) abused

“I can confirm this bug,” Exim project team member Heiko Schlittermann wrote on a bug-tracking site, ArsTechnica reported. “It looks like a serious security issue to me.”

Censys says out of roughly 6.5 million public-facing SMTP email servers, 4.8 million are running Exim. Furthermore, 1.5 million are running an old, vulnerable version. So far, there have been no reports of in-the-wild abuse of the vulnerability, but now that it is out in the limelight, it’s only a matter of time before threat actors start scanning the internet for vulnerable instances. 

To make the attack work, the victims would still need to run the attachment and install the malware. However, threat actors have been running some highly sophisticated social engineering attacks lately, which means the risk of infection is very real.

With phishing still being one of the most popular methods of malware delivery, flawed email servers are a highly-regarded commodity. For example, back in 2020, a Russian state-sponsored threat actor abused an Exim flaw, found almost half a year earlier, to gain access to the email server. 

IT teams running Exim should make sure they patch it to 4.98, since this is the first fixed version.

More from TechRadar Pro

TOPICS

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
Flag of the People's Republic of China overlaid with a technological network of wires and circuits.
One of the biggest flaws exploited by Salt Typhoon hackers has had a patch available for years
Outlook
Dangerous Microsoft Outlook flaw could let hackers send out malware via email
Security
Experts warn millions of email servers could be vulnerable to attack
the YouTube logo on a screen in front of other YouTube logos covering a black background
Worrying YouTube security flaw exposed billions of user emails
A stylized depiction of a padlocked WiFi symbol sitting in the centre of an interlocking vault.
Top file synchronization tool Rsync security flaws mean up to 660,000 servers possibly affected
An image of network security icons for a network encircling a digital blue earth.
Industrial networks exposed to attack by faulty Moxa devices
Latest in Security
Data leak
Top home hardware firm data leak could see millions of customers affected
Representational image depecting cybersecurity protection
Third-party security issues could be the biggest threat facing your business
A stylized depiction of a padlocked WiFi symbol sitting in the centre of an interlocking vault.
Broadcom warns of worrying security flaws affecting VMware tools
Android Logo
Devious new Android malware uses a Microsoft tool to avoid being spotted
URL phishing
HaveIBeenPwned owner suffers phishing attack that stole his Mailchimp mailing list
Ransomware
Cl0p resurgence drives ransomware attacks to new highs in 2025
Latest in News
Buzz Lightyear Space Ranger Spin Rennovations
Disney’s giving a classic Buzz Lightyear ride a tech overhaul – here's everything you need to know
Hisense U8 series TV on wall in living room
Hisense announces 2025 mini-LED TV lineup, with screen sizes up to 100 inches – and a surprising smart TV switch
Nintendo Music teaser art
Nintendo Music expands its library with songs from Kirby and the Forgotten Land and Tetris
Opera AI Tabs
Opera's new AI feature brings order to your browser tab chaos
An image of Pro-Ject's Flatten it closed and opened
Pro-Ject’s new vinyl flattener will fix any warped LPs you inadvertently buy on Record Store Day
The iPhone 16 Pro on a grey background
iPhone 17 Pro tipped to get 8K video recording – but I want these 3 video features instead