RCE vulnerability affects half of mail servers on the internet

A security issue in remote execution (RCE from remote command execution) affects more than half of Internet e-mail servers, according to of Qualys security.

The vulnerability affects Exim, a mail transfer agent (MTA), which is software that runs on e-mail servers to transmit messages from sender to recipient.

RCE

According to one research Of all mail servers visible on the Internet, 57% (507,389) of all servers run Exim.

In a security alert, Qualys, a cybersecurity company that specializes in cloud security, said it found a very dangerous vulnerability in Exim installations in versions 4.87 to 4.91.

The vulnerability is described as RCE and is different from, but equally dangerous as, a remote code execution vulnerability that allows a local or remote attacker to run on the Exim server as root.

Qualys said the vulnerability could be exploited directly by a local attacker who has a physical presence on an email server, even with a low-profile account.

But the real danger comes from remote hackers who exploit the vulnerability, as they can scan the Internet for vulnerable servers and compromise systems.


"Due to the extreme complexity of the Exim code, we can not guarantee that this method of exploitation is unique, there may be faster methods."

In addition, the Qualys team reports that the vulnerability was fixed completely by accident:

The vulnerability was fixed with the release of Exim 4.92 on February 10, 2019, but at the time version 4.92 was released, they were unaware of the security vulnerability.

It was discovered by the Qualys team when testing older versions of Exim, and are now warning Exim users to update to version 4.92.

________________

iGuRu.gr The Best Technology Site in Greecefgns

every publication, directly to your inbox

Join the 2.087 registrants.

Written by giorgos

George still wonders what he's doing here ...

Leave a reply

Your email address is not published. Required fields are mentioned with *

Your message will not be published if:
1. Contains insulting, defamatory, racist, offensive or inappropriate comments.
2. Causes harm to minors.
3. It interferes with the privacy and individual and social rights of other users.
4. Advertises products or services or websites.
5. Contains personal information (address, phone, etc.).