CVE-2019-10149
Description
A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message() function in /src/deliver.c may lead to remote command execution.
In plain language
AI Act nowCVE-2019-10149 is a serious Exim email server flaw (in versions 4.87–4.91) that can let an attacker run commands remotely without any login, so most small businesses should treat this as urgent if you use Exim.
CVE-2019-10149 is an unauthenticated remote command execution flaw in Exim (deliver_message() in /src/deliver.c) caused by improper recipient address validation, allowing network-based attackers to trigger arbitrary command execution.
What to do now
- Check whether you are running Exim and whether its version is in the range 4.87 to 4.91 (inclusive).
- If you are affected, upgrade Exim to the vendor-fixed version listed in the Exim security advisory for CVE-2019-10149.
- If you can’t upgrade immediately, follow the mitigation steps from the same Exim security advisory (or your OS vendor’s security update) until the upgrade is completed.
- After upgrading, verify Exim is running the updated version and that the mail service still processes messages normally.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Required action: Apply updates per vendor instructions.
Exploit details including PoC links, Metasploit modules, and scanner templates are available after registration.
View exploit detailsAttack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
1 techniqueReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2019-10149 and every CVE in our database. Create a free account — no credit card required.
Create Free Account