Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2018-6789

97
FAUCET Score

CVE-2018-6789 is a critical buffer overflow vulnerability (CWE-120) in the base64d function of the Exim SMTP listener, affecting Exim versions prior to 4.90.1 and various Debian/Ubuntu distributions. This flaw allows for unauthenticated remote code execution via a crafted message, posing a severe risk with a CVSS score of 9.8. The vulnerability is actively exploited, including in known ransomware campaigns, and has public exploit code available on ExploitDB. It has garnered significant community discussion and media attention, including being listed by the NSA as actively abused by Chinese state-sponsored hackers.

Impacted Technologies

VendorProductVersion(s)CPE
< 4.90.1CPE matchmatch criteria
cpe:2.3:a:exim:exim:*:*:*:*:*:*:*:*
7.0CPE matchmatch criteria
cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:*
8.0CPE matchmatch criteria
cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*
9.0CPE matchmatch criteria
cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*
14.04CPE matchmatch criteria
cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:esm:*:*:*

CVSS Data

CVSS version used by this source: 3.1

9.8CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
82.14%
Probability of exploitation in next 30 days
EPSS Percentile
99.6%
Percentile rank of EPSS score among Peer Group
As of 2026-07-24
Model: v2026.06.15
Added to KEV · Nov 3, 2021
ExploitDB: EDB-45671 · Oct 24, 2018
This CVE's current EPSS score of 0.8214 is in the 98th percentile among its peer group of 36,829 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Patches (7)

boschvendor investigatingvia llm_extracted
citrix_adcvendor investigatingvia llm_extracted
View patch
esetvendor investigatingvia llm_extracted
View patch
giteavendor investigatingvia llm_extracted
View patch
googlevendor investigatingvia llm_extracted
rocketchatvendor investigatingvia llm_extracted
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 5Fixed in: exim

Vendor Advisories (7)

giteallm-gitea-eda4b5f91b58af0c
Dec 17, 2025
redhatCVE-2018-6789Critical

exim: buffer overflow in b64decode() function, possibly leading to remote code execution

Feb 7, 2018
googlellm-google-2a6779d0a0eb5db4

Security Advisory for CVE-2018-6789

esetllm-eset-4b09011359c51b3e
citrix_adcllm-citrix_adc-6728f65ef5c56045
boschllm-bosch-1903cd4fda829386

Security Advisory for CVE-2018-6789

rocketchatllm-rocketchat-694fe01dadbedbf3

References

cisa.gov / known-exploited-vulnerabilities-catalog
US Government Resource
openwall.com / lists/oss-security/2018/02/10/2
Mailing ListThird Party Advisory
packetstormsecurity.com / files/162959/Exim-base64d-Buffer-Overflow.html
ExploitThird Party AdvisoryVDB Entry
devco.re / blog/2018/03/06/exim-off-by-one-RCE-exploiting-CVE-2018-6789-en
ExploitThird Party Advisory
exim.org / static/doc/security/CVE-2018-6789.txt
Vendor Advisory
git.exim.org / exim.git/commit/cf3cd306062a08969c41a1cdd32c6855f1abecf1
Patch
lists.debian.org / debian-lts-announce/2018/02/msg00009.html
Mailing ListThird Party Advisory
usn.ubuntu.com / 3565-1
Third Party Advisory
debian.org / security/2018/dsa-4110
Mailing ListThird Party Advisory
exploit-db.com / exploits/44571
ExploitThird Party AdvisoryVDB Entry
exploit-db.com / exploits/45671
ExploitThird Party AdvisoryVDB Entry
openwall.com / lists/oss-security/2018/02/07/2
Mailing ListThird Party Advisory
securityfocus.com / bid/103049
Broken LinkThird Party AdvisoryVDB Entry
securitytracker.com / id/1040461
Broken LinkThird Party AdvisoryVDB Entry