Exim known exploited vulnerabilities
CISA lists 5 Exim CVEs as exploited in the wild. 0 were added in the last 12 months (latest 2022-03-25), and 1 are known to be used in ransomware campaigns.
Year = when CISA added the CVE to the catalog (KEV started in November 2021).
Patch first: highest EPSS right now
EPSS is FIRST's estimate of the chance a CVE is exploited in the next 30 days.
- CVE-2019-10149 (Mail Transfer Agent (MTA)): EPSS 100.0%, added 2022-01-10
- CVE-2018-6789 (Exim): EPSS 82.1%, added 2021-11-03
- CVE-2010-4344 (Exim): EPSS 71.7%, added 2022-03-25
- CVE-2019-16928 (Exim Internet Mailer): EPSS 41.6%, added 2022-03-03
- CVE-2010-4345 (Exim): EPSS 18.0%, added 2022-03-25
Most affected Exim products
Exim (3), Exim Internet Mailer (1), Mail Transfer Agent (MTA) (1).
All Exim CVEs in KEV
| CVE | Product | Flaw | Added | Federal due | EPSS | Ransomware |
|---|---|---|---|---|---|---|
| CVE-2010-4345 | Exim | Privilege Escalation | 2022-03-25 | 2022-04-15 | 18.0% | – |
| CVE-2010-4344 | Exim | Heap-Based Buffer Overflow | 2022-03-25 | 2022-04-15 | 71.7% | – |
| CVE-2019-16928 | Exim Internet Mailer | Out-of-bounds Write | 2022-03-03 | 2022-03-17 | 41.6% | – |
| CVE-2019-10149 | Mail Transfer Agent (MTA) | Mail Transfer Agent (MTA) Improper Input Validation | 2022-01-10 | 2022-07-10 | 100.0% | – |
| CVE-2018-6789 | Exim | Buffer Overflow | 2021-11-03 | 2022-05-03 | 82.1% | Yes |
Federal due dates bind US federal civilian agencies (CISA binding operational directives); everyone else can use them as a priority hint. Sources: CISA KEV, FIRST EPSS.
Read next: Which CVEs to patch first this week · All vendors