CVE-2019-10149

CVE Published 2019-06-05
Related CWE(s) CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')
Related Vendor(s) debian, exim, canonical
Related Product(s) exim, ubuntu_linux, debian_linux
Exploitation Reported (CISA KEV) 2022-01-10
CVSS 3 Base Score 9.0 (CRITICAL)
CVSS 3 Attack Complexity HIGH
CVSS 3 Attack Vector NETWORK

A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message() function in /src/deliver.c may lead to remote command execution.

Cyber Threat Graph Context

Explore how this CVE relates to the wider threat graph

Threat Reports Related to CVE-2019-10149

Report

APT44: Unearthing Sandworm

This report from researchers at Mandiant marks the graduation of the Sandworm intrusion set to the Mandiant APT label: APT44. It provides a ...

Associated CAPEC Patterns

References