CVE-2017-16943 is a critical use-after-free vulnerability in the Exim SMTP daemon, specifically affecting versions 4.88 and 4.89, including those in Debian Linux. This flaw allows remote, unauthenticated attackers to execute arbitrary code or cause a denial of service through specially crafted BDAT commands. With a CVSS score of 9.8 and an EPSS score indicating high exploitability, the impact is severe, leading to complete compromise of confidentiality, integrity, and availability. While no public exploit code is readily available in common frameworks like Metasploit or ExploitDB, the vulnerability garnered significant media attention and community discussion, highlighting its potential for widespread impact on internet email servers.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
4.88CPE matchmatch criteria | cpe:2.3:a:exim:exim:4.88:-:*:*:*:*:*:* | ||
4.89CPE matchmatch criteria | cpe:2.3:a:exim:exim:4.89:-:*:*:*:*:*:* | ||
9.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.