Exim NTLM Challenge Out-Of-Bounds Read Information Disclosure Vulnerability
CVE-2023-42114
What is CVE-2023-42114?
The identified vulnerability in Exim involves a flaw in the handling of NTLM challenge requests, which permits remote attackers to exploit insufficient validation of user-supplied data. This oversight enables attackers to read beyond the end of allocated data structures, potentially leading to the disclosure of sensitive information linked to the service account used by the Exim Mail Server. Notably, no authentication is required to exploit this vulnerability, heightening the risk for affected installations.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Exim exim 4.95
References
EPSS Score
13% chance of being exploited in the next 30 days.
CVSS V3.1
CVSS V3.0
Timeline
Vulnerability published
Vulnerability Reserved
