CVE-2010-4345
CVSS 3.1 Score 7.8 of 10 (high)
Details
Published Dec 14, 2010
Updated: Dec 19, 2024
Summary
CVE-2010-4345 is a vulnerability affecting Exim version 4.72 and earlier. This issue allows local users to elevate their privileges by manipulating the exim user account's ability to specify an alternate configuration file. By introducing arbitrary commands in a directive, such as spool_directory, attackers can gain unauthorized access to sensitive system information or even execute malicious code. This vulnerability poses a significant security risk and requires immediate attention from system administrators to patch or mitigate the issue.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- University Of Cambridge Exim
- Ubuntu Linux
- Open SUSE
- Debian
Affected Vendors
- Debian
- Opensuse
- Canonical System
- Export-Import Bank of the United States