HomeSecurityMillions of Exim servers give root access to hackers. How?

Millions of Exim servers give root access to hackers. How?

Millions of Exim servers are vulnerable to a security flaw that could allow attackers to execute malicious code with root privileges.

All Exim servers running version 4.92.1 and earlier are vulnerable , the Exim team said . Version 4.92.2 was released on Friday, September 6, to address the issue.

 Exim servers

The problem may not seem important to many, but Exim is one of the most widely used software. Exim is a mail transfer agent (MTA), that is, software that runs in the background of email servers. While email servers often send or receive messages, they also act as a “relay” for other people’s emails. This, essentially, is the job of the MTA.

Exim is the most widely used MTA today, with a market share of over 57%, according to a June 2019 survey. Its success can be attributed to the fact that it has been bundled with a number of Linux, from Debian to Red Hat.

 Exim servers

Vulnerability

If the Exim server is configured to accept incoming TLS, a hacker can send a malicious backslash-null sequence appended to the end of an SNI packet and execute malicious code with root privileges.

The issue was reported in early July by a security researcher named Zerons and has been patched in complete secrecy by the Exim team.

The secrecy was justified due to how easily the vulnerability can be exploited , root access, and the large number of vulnerable servers.

Authoritative sources report over 5.2 million Exim servers running version 4.92.1 and later (i.e. the vulnerable versions).

root

Server owners can mitigate this vulnerability – listed as CVE-2019-15846 – by disabling TLS support for the Exim server. However, this is not a permanent and 100% secure solution, as it exposes email traffic in cleartext and makes it vulnerable to sniffing attacks and eavesdropping.

This mitigation is not recommended for Exim owners living in the EU, as it can expose their companies to data leaks and hefty GDPR fines.

root

It is worth noting that by default, Exim installations do not have TLS support enabled. However, there are Exims included in Linux distros that offer TLS enabled by default. Since most server administrators use OS images and few perform the Exim download process manually, most Exim instances are likely vulnerable.

Additionally, Exim servers with cPanel, a popular web hosting software, also support TLS by default. The good news is that the creators of cPanel immediately integrated the Exim patch into an updated version of cPanel.

Security experts warn that the Exim security flaw will be readily exploited.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS