HomeSecurityExim mail server: Vulnerabilities allow systems to be compromised

Exim mail server: Vulnerabilities allow systems to be compromised

Researchers at the National Institute of Standards and Technology (NIST) have revealed critical vulnerabilities in the popular Exim mail server. The findings show that, under certain circumstances, remote attackers could gain complete control of vulnerable systems, putting organizations and service providers worldwide at serious risk.

Exim

Which versions are affected?

The security issues concern Exim version 4.99, when it is configured with SQLite hints database.

While not all Exim installations are affected, experts point out that many production infrastructures use exactly these settings, often without administrators being aware of the potential risk.

Exim mail server: Two critical vulnerabilities under the microscope

The NIST research team has identified two separate, but extremely serious security vulnerabilities related to the SQLite implementation in Exim.

See also: Beware! Zero-day vulnerability in WatchGuard Firebox firewalls

The first concerns an incomplete SQL injection fix, known as CVE-2025-26794. The issue arises from the incorrect handling of single-quote characters in database queries. In practice, this allows attackers to inject malicious SQL code via specially crafted SMTP commands, using email addresses containing SQL injection payloads.

The second vulnerability is even more concerning on a technical level. It is a heap buffer overflow, which is caused when unvalidated fields from the database are used as array boundaries. When processing this data by the bloom filter code, the code can write far beyond the allowed memory limits.

Exim mail server: Vulnerabilities allow systems to be compromised

Accurate memory corruption and possible attack scenarios

According to the researchers, the above can lead to memory corruption, including the ability to target specific heap locations and write arbitrary byte values.

While a fully functional remote code execution (RCE) has yet to be demonstrated, experts warn that the level of control offered by this vulnerability is particularly dangerous. Given enough time, expertise, and resources, a determined attacker could bypass modern defenses and achieve a complete system compromise.

See also: React2Shell: The Log4j moment for front end development

When are loopholes exploitable?

The vulnerabilities require specific configurations. Mail servers must be compiled with SQLite support and use rate-limited Access Control Lists, which incorporate data that an attacker can control, such as sender addresses.

Particularly dangerous are settings that use the “per_addr” function with explicit sender address keys or “unique” parameters based on values ​​derived from the SMTP session.

Why modern defenses are not enough

The researchers were able to demonstrate successful heap corruption and memory manipulation, but they did not complete a full RCE attack, due to mechanisms such as ASLR (Address Space Layout Randomization). However, the history of software security shows that such protections often fail in the face of complex exploit chains.

That's why the community is treating the findings as a high priority issue.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Exim mail server: Vulnerabilities allow systems to be compromised

Remedial actions and recommendations

Exim maintainers have already been notified and are working on fixes. Suggested measures include proper single quote escaping to prevent SQL injection and strict validation of database field sizes before they are used as array boundaries.

See also: UEFI vulnerability allows DMA attacks on ASRock, ASUS, GIGABYTE, MSI motherboards

Until official updates are released, system administrators are advised to consider temporary solutions, such as disabling SQLite hints support or restricting ACL ratelimits based on sender addresses.

Coordinated disclosure for security purposes

The NIST research team follows a coordinated disclosure process, giving developers the necessary time to fix problems before all the technical details. In an era where attacks on email infrastructure are increasing, timely response and proper information remain the most powerful weapon of defense.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS