Impact
Exim versions older than 4.99.5 mishandle the force_command directive for a pipe transport within .forward files, which allows an attacker to execute arbitrary commands with the privileges of the Exim daemon. This flaw is classified as a privilege‑elevation vulnerability (CWE‑829) and can compromise the confidentiality, integrity, and availability of the mail server environment.
Affected Systems
All instances of Exim running a version prior to 4.99.5 are affected. The vulnerability applies regardless of the operating system or host configuration, as long as the mail server processes .forward files and supports pipe transports.
Risk and Exploitability
The CVSS score of 7.4 indicates a high severity of the flaw, but the EPSS score of less than 1% suggests a very low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector involves creating or modifying a .forward file that Exim reads; an attacker must have the ability to write such a file. No publicly released exploit is documented, but the lack of an exploit does not mitigate the risk of privileged execution if an attacker can influence the .forward content.
OpenCVE Enrichment
Debian DSA