CVE Tools

Description

A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message() function in /src/deliver.c may lead to remote command execution.

In plain language

AI Act now

CVE-2019-10149 is a serious Exim email server flaw (in versions 4.87–4.91) that can let an attacker run commands remotely without any login, so most small businesses should treat this as urgent if you use Exim.

Executive summary

CVE-2019-10149 is an unauthenticated remote command execution flaw in Exim (deliver_message() in /src/deliver.c) caused by improper recipient address validation, allowing network-based attackers to trigger arbitrary command execution.

If affected, business impact
Full server takeoverMalicious command executionEmail service disruptionData theft risk

What to do now

  1. Check whether you are running Exim and whether its version is in the range 4.87 to 4.91 (inclusive).
  2. If you are affected, upgrade Exim to the vendor-fixed version listed in the Exim security advisory for CVE-2019-10149.
  3. If you can’t upgrade immediately, follow the mitigation steps from the same Exim security advisory (or your OS vendor’s security update) until the upgrade is completed.
  4. After upgrading, verify Exim is running the updated version and that the mail service still processes messages normally.
Patch / advisory Some work to apply

CVSS Vector Breakdown

AV:NAC:LPR:NUI:NS:UC:HI:HA:H
Exploitability
AV:NAttack Vector
Network
AC:LAttack Complexity
Low
PR:NPrivileges Required
None
UI:NUser Interaction
None
Scope
S:UScope
Unchanged
Impact
C:HConfidentiality
High
I:HIntegrity
High
A:HAvailability
High

Weaknesses

Affected Products

and 2 more affected products View all →

Exploitability

CISA Known Exploited Vulnerability
Added to KEV:Jan 10, 2022
Remediation due:Jul 10, 2022

Required action: Apply updates per vendor instructions.

4 exploit sources identified

Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.

View exploit details
Official Patch Available

Attack Graph

Products CVE Techniques Tactics

Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/ + scroll to zoom, or go fullscreen.

MITRE ATT&CK

1 technique
Execution
View detailed technique mapping

References

and 25 more references View all →

Unlock Complete Vulnerability Intelligence

Get the full picture for CVE-2019-10149 and every CVE in our database. Create a free account — no credit card required.

Create Free Account
Plain-language analysis
Impact assessment and exploitation scenario in plain English
Attack graph visualization
Interactive attack path and kill chain mapping
Exploit details & PoC links
ExploitDB, Metasploit, GitHub PoCs with direct links
Nuclei scanner templates
Ready-to-use vulnerability scanner templates
Full remediation guide
Patch instructions, workarounds, and compliance impact
Interactive AI chat
Ask questions about this vulnerability in natural language
Related vulnerabilities
Semantically similar CVEs and attack patterns
REST API & MCP access
Integrate vulnerability data into your workflows