Article 6P59P Exim vulnerability affecting 1.5 million servers lets attackers attach malicious files

Exim vulnerability affecting 1.5 million servers lets attackers attach malicious files

by
Dan Goodin
from Ars Technica - All content on (#6P59P)
exploit-vulnerability-security-800x450.j

Enlarge

More than 1.5 million email servers are vulnerable to attacks that can deliver executable attachments to user accounts, security researchers said.

The servers run versions of the Exim mail transfer agent that are vulnerable to a critical vulnerability that came to light 10 days ago. Tracked as CVE-2024-39929 and carrying a severity rating of 9.1 out of 10, the vulnerability makes it trivial for threat actors to bypass protections that normally prevent the sending of attachments that install apps or execute code. Such protections are a first line of defense against malicious emails designed to install malware on end-user devices.

A serious security issue

I can confirm this bug," Exim project team member Heiko Schlittermann wrote on a bug-tracking site. It looks like a serious security issue to me."

Read 4 remaining paragraphs | Comments

External Content
Source RSS or Atom Feed
Feed Location http://feeds.arstechnica.com/arstechnica/index
Feed Title Ars Technica - All content
Feed Link https://arstechnica.com/
Reply 0 comments