Exim NTLM Challenge Out-Of-Bounds Read Information Disclosure Vulnerability
CVE-2023-42114

3.7LOW

Key Information:

Vendor

Exim

Status
Vendor
CVE Published:
3 May 2024

What is CVE-2023-42114?

The identified vulnerability in Exim involves a flaw in the handling of NTLM challenge requests, which permits remote attackers to exploit insufficient validation of user-supplied data. This oversight enables attackers to read beyond the end of allocated data structures, potentially leading to the disclosure of sensitive information linked to the service account used by the Exim Mail Server. Notably, no authentication is required to exploit this vulnerability, heightening the risk for affected installations.

Affected Version(s)

Exim exim 4.95

References

EPSS Score

12% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
3.7
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.