CVE-2025-67896
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 7epss 0.4%
exploitation probability
0.4%top 66% of all CVEs
observed exploitation
nono source reports it
In short
Exim email servers with specific rate-limit settings can crash or run malicious code when receiving specially crafted messages. An attacker doesn't need valid credentials, just network access to the mail server.
Technical detail
Exim before 4.99.1 is vulnerable to heap-based buffer overflow (CWE-122) when non-default rate-limit configurations are enabled. The vulnerability occurs due to unsafe casting of database records directly to internal structures without validation. Remote attackers can trigger memory corruption via malformed input, potentially achieving code execution or denial of service.
Summary generated and translated by AI from the official description.
Exim before 4.99.1, with certain non-default rate-limit configurations, allows a remote heap-based buffer overflow because database records are cast directly to internal structures without validation.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:H/A:L
Affected products
Exim · Exim