News

57% of mail-servers have critical vulnerability

Qualys researchers discovered a critical vulnerability that affects more than half of mail servers.

The problem was detected in the Exim Mail Transfer Agent (MTA) software, which is installed on mail servers for delivering emails from the sender to the addressee.

According to data for June 2019, Exim is set at 57% (507,389) of all servers found on the Internet. However, there is information that in fact the number of Exim installations exceeds this number tenfold and is estimated as 5.4 million.

Detected by Qualys experts vulnerabilities affect software versions from 4.87 to 4.91. The vulnerability allows a remote/local attacker to launch commands on the mail server with superuser privileges.

Read also: More than 50,000 MS-SQL and PHPMyAdmin servers were infected by rootkits and miners

Local attacker, even with the lowest privileges, can exploit it immediately. However, the most dangerous are remote attackers who scan the Internet for vulnerable servers and are able to take control of vulnerable systems.

For remote exploitation of the default configuration, an attacker must maintain a connection to the vulnerable server for seven days (by sending one byte every few minutes).

“For transmitting one by one for each day (by transmitting one byte every few minutes). However, we cannot guarantee that this method of exploitation is unique; faster methods may exist”, – admit researchers.

In addition, they indicate that vulnerability can be exploited remotely not only with the default configuration settings.

The problem was fixed in the version of Exim 4.92, released in February of this year. It is noteworthy that at the time of new software’s version release, vulnerability was not yet known, and it was fixed accidentally. Researchers discovered the problem only during the audit of old Exim versions.

Vulnerability assigned an identifier CVE-2019-10149, in Qualys, it passes under the name “Return of the WIZard“.

Source: https://www.openwall.com

Polina Lisovskaya

I works as a marketing manager for years now and loves searching for interesting topics for you

Recent Posts

Remove Rengine.click Pop-up Ads

About Rengine.click Rengine.click pop-ups can not expose out of the blue. If you have actually…

21 hours ago

Remove Xzcczxxx.xyz Pop-up Ads

About Xzcczxxx.xyz Xzcczxxx.xyz pop-ups can not introduce out of nowhere. If you have clicked on…

21 hours ago

Remove Xefkqo.info Pop-up Ads

About Xefkqo.info Xefkqo.info pop-ups can not open out of nowhere. If you have actually clicked…

22 hours ago

Remove Rt9.lol Pop-up Ads

About Rt9.lol Rt9.lol pop-ups can not introduce out of the blue. If you have actually…

1 day ago

Remove Sex-hd.xxx Pop-up Ads

About Sex-hd.xxx Sex-hd.xxx pop-ups can not launch out of the blue. If you have actually…

2 days ago

Remove Curestin.co.in Pop-up Ads

About Curestin.co.in Curestin.co.in pop-ups can not introduce out of nowhere. If you have actually clicked…

3 days ago