Impact
Exim versions prior to 4.99.5 are susceptible to a directory traversal flaw that is triggered through the queue-name argument. An attacker can construct a queue name containing path traversal characters, causing Exim to read files outside its spool directory. This flaw allows the attacker to view sensitive files and gain privileges within the host system, effectively escalating their access.
Affected Systems
All Exim releases older than 4.99.5 run on any platform that serves mail via SMTP. The vulnerability affects the mail transfer agent itself, independent of the underlying operating system. Systems with a deployed Exim installation that has not applied the 4.99.5 update remain at risk.
Risk and Exploitability
The CVSS score of 8.4 signals a high severity risk, while the EPSS score of less than 1% implies that exploitation is currently unlikely. The vulnerability is not cataloged in CISA’s KEV registry. Based on the description the attack vector is through specially crafted SMTP traffic targeting the queue-name handling logic. Successful exploitation would permit an attacker to read arbitrary files and elevate privileges on the afflicted host.
OpenCVE Enrichment
Debian DSA