CVE-2023-42118 is a critical remote code execution vulnerability affecting Exim mail servers utilizing libspf2, specifically within the parsing of SPF macros. This flaw allows unauthenticated, network-adjacent attackers to execute arbitrary code due to an integer underflow when processing user-supplied data. With a CVSS score of 8.8 (High), exploitation requires low attack complexity and can lead to complete compromise of confidentiality, integrity, and availability. While not currently listed on the KEV catalog, its high media coverage and community discussion indicate significant attention, though no public exploit code is yet available.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:libspf2_project:libspf2:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.