Exim developers have released updates for three of the zero-day vulnerabilities disclosed last week through Trend Micro's Zero Day Initiative (ZDI).

The most serious of these vulnerabilities was discovered by an anonymous security. The zero-day bug (CVE-2023-42115) is due to an Out-of-bounds Write weakness in the SMTP service and can be exploited by remote attackers, without authentication, to execute code.
“The specific flaw exists in the service (TCP port 25 by default). The problem arises from the lack of proper validation of user-supplied data, which can lead to “write past the end of a buffer”, reports ZDI.
See also: Microsoft Defender: No longer flags Tor Browser as malware
“Fix a possible OOB write in external authentication,” says the Exim development team in the changelog for version 4.96.1, which was released.
The Exim team is also patching another zero-day vulnerability that allows remote code execution (CVE-2023-42114) and a third that leads to information disclosure (CVE-2023-42116).
As Exim developer Heiko Schlittermannon Friday, the new fixes were already “available in a protected repository” and “ready for implementation by distribution maintainers.”
See also: Arm: Warns of flaws in Mali GPU
Three other zero-day Exim vulnerabilities that need to be fixed:
- CVE-2023-42117: Allows remote code execution
- CVE-2023-42118: Allows remote code execution
- CVE-2023-42119: Allows information disclosure

As mentioned above, the most serious of the Exim zero-day vulnerabilities is CVE-2023-42115. It has been rated 9.8/10 on the vulnerability. But Exim developers say that its successful exploitation depends on the use of external authentication on the targeted servers.
Although 3.5 million Exim servers are exposed online, according to Shodan, this requirement drastically reduces the number of Exim mail servers that are ultimately at risk.
An analysis from watchTowr Labs confirms Exim and says the vulnerabilities require special conditions to be exploited.
See also: ShadowSyndicate has used 7 ransomware families in the last year
watchTowr Labs also provided a list of all the configuration requirements on vulnerable Exim servers needed for successful exploitation:
| CVE | CVSS | Requirements |
| CVE-2023-42115 | 9.8 | “External” authentication scheme configured and available |
| CVE-2023-42116 | 8.1 | “SPA” module (used for NTLM auth) configured and available |
| CVE-2023-42117 | 8.1 | Exim Proxy (different to a SOCKS or HTTP proxy) in use with untrusted proxy server |
| CVE-2023-42118 | 7.5 | “SPF” condition used in an ACL |
| CVE-2023-42114 | 3.7 | “SPA” module (used for NTLM auth) configured to auth the Exim server to an upstream server |
| CVE-2023-42119 | 3.1 | An untrusted DNS resolver |
“Most of us don’t need to worry,” said a watchTowr researcher.
"So, our advice is the usual – patch when you can, as soon as the patches are available [..] But in the meantime, don't panic," he said.
IT and technology companies often disclose security issues in platforms – after all, no software is invulnerable. However, these issues are even more serious when it comes to so-called “zero-day bugs”. Zero-day vulnerabilities are those vulnerabilities that attackers are able to exploit before developers create and distribute fixes. These vulnerabilities are particularly dangerous, as malicious users can have continued access to vulnerable systemsuntil the vulnerability is discovered and fixed. The 9.8/10 vulnerability severity rating for CVE-2023-42115 highlights the need for immediate implementation of the Exim patch that is now available.
Source: www.bleepingcomputer.com
