← Back to browse · API

CVE-2010-4345

Severity
HIGH
CVSS
7.8
EPSS
0.18105
Risk score
62.54
CISA KEV
Yes
PoC
No
Published
2010-12-14
Modified
2025-10-22
First seen
2026-08-07
Aliases
EUVD-2010-4314, GHSA-QQ6C-P3FX-6QCX
Products
Exim:Exim, n/a:n/a n/a
Sources
cisa.gov CVE-2010-4345
euvd EUVD-2010-4314

Description

Exim 4.72 and earlier allows local users to gain privileges by leveraging the ability of the exim user account to specify an alternate configuration file with a directive that contains arbitrary commands, as demonstrated by the spool_directory directive.

References