CVE-2016-1531 is a local privilege escalation vulnerability affecting Exim versions prior to 4.86.2 when installed with setuid root. An attacker can exploit this flaw via the perl_startup argument to gain elevated privileges on the system. With a CVSS score of 7.0 (High), this vulnerability has a low attack complexity but allows for full confidentiality, integrity, and availability impact. While not on the KEV catalog, multiple public exploits, including a Metasploit module, exist, yet it has received minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 4.86CPE matchmatch criteria | cpe:2.3:a:exim:exim:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.4 InfoSec Media, 0.1 Vendor Blog, and 0.0 Security Researcher mentions.
exim: local root privilege escalation for configurations with perl_startup
Mar 2, 2016Security Advisory for CVE-2016-1531
Security Advisory for CVE-2016-1531