Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2019-10149

98
FAUCET Score

CVE-2019-10149 is a critical remote command execution vulnerability affecting Exim mail server versions 4.87 through 4.91, impacting various Canonical and Debian Linux distributions. This flaw stems from improper validation of recipient addresses within the deliver_message() function. With a CVSS score of 9.8 (CRITICAL), it allows unauthenticated attackers to execute arbitrary commands remotely with low attack complexity, leading to complete compromise of confidentiality, integrity, and availability. The vulnerability is actively exploited in the wild, with public exploit code available in Metasploit and ExploitDB, and has garnered significant community discussion and media coverage due to its widespread impact on millions of mail servers.

Impacted Technologies

VendorProductVersion(s)CPE
>= 4.87, <= 4.91CPE matchmatch criteria
cpe:2.3:a:exim:exim:*:*:*:*:*:*:*:*
18.04CPE matchmatch criteria
cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:*
18.10CPE matchmatch criteria
cpe:2.3:o:canonical:ubuntu_linux:18.10:*:*:*:*:*:*:*
9.0CPE matchmatch criteria
cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.0

9.0CRITICAL

CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
CHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
2.2
Impact Score
6.0
CvssVersion
3.0

Exploit Intelligence

EPSS Score
99.96%
Probability of exploitation in next 30 days
EPSS Percentile
100.0%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
Added to KEV · Jan 10, 2022
Metasploit: Exim 4.87 - 4.91 Local Privilege Escalation · Jun 5, 2019
ExploitDB: EDB-47307 · Aug 26, 2019
This CVE's current EPSS score of 0.9996 is in the 100th percentile among its peer group of 36,897 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Patches (6)

boschvendor investigatingvia llm_extracted
citrix_adcvendor investigatingvia llm_extracted
View patch
esetvendor investigatingvia llm_extracted
View patch
giteavendor investigatingvia llm_extracted
View patch
googlevendor investigatingvia llm_extracted
rocketchatvendor investigatingvia llm_extracted

Vendor Advisories (7)

giteallm-gitea-686d34369c2daa85
Dec 17, 2025
redhatCVE-2019-10149Critical

exim: Remote command execution in deliver_message() function in /src/deliver.c

Jun 4, 2019
googlellm-google-498c93e718ea9bff

Security Advisory for CVE-2019-10149

esetllm-eset-60e37bd31549c4df
citrix_adcllm-citrix_adc-ee1b7b7b7fd03bc1
boschllm-bosch-c8777714cda7e1bd

Security Advisory for CVE-2019-10149

rocketchatllm-rocketchat-41a6566d8e0d3501

References

cisa.gov / known-exploited-vulnerabilities-catalog
US Government Resource
lists.opensuse.org / opensuse-security-announce/2019-06/msg00020.html
Mailing ListThird Party Advisory
packetstormsecurity.com / files/153218/Exim-4.9.1-Remote-Command-Execution.html
ExploitThird Party AdvisoryVDB Entry
packetstormsecurity.com / files/153312/Exim-4.91-Local-Privilege-Escalation.html
ExploitThird Party AdvisoryVDB Entry
packetstormsecurity.com / files/154198/Exim-4.91-Local-Privilege-Escalation.html
ExploitThird Party AdvisoryVDB Entry
bugzilla.redhat.com / show_bug.cgi
Issue TrackingThird Party Advisory
seclists.org / fulldisclosure/2019/Jun/16
Mailing ListThird Party Advisory
seclists.org / bugtraq/2019/Jun/5
Mailing ListThird Party Advisory
security.gentoo.org / glsa/201906-01
Third Party Advisory
usn.ubuntu.com / 4010-1
Third Party Advisory
debian.org / security/2019/dsa-4456
Third Party Advisory
exim.org / static/doc/security/CVE-2019-10149.txt
Vendor Advisory
openwall.com / lists/oss-security/2019/06/05/2
Mailing ListThird Party Advisory
openwall.com / lists/oss-security/2019/06/05/3
Mailing ListPatchThird Party Advisory
openwall.com / lists/oss-security/2019/06/05/4
ExploitMailing List
openwall.com / lists/oss-security/2019/06/06/1
ExploitMailing ListThird Party Advisory
openwall.com / lists/oss-security/2019/07/25/6
Mailing ListThird Party Advisory
openwall.com / lists/oss-security/2019/07/25/7
Mailing ListThird Party Advisory
openwall.com / lists/oss-security/2019/07/26/4
Mailing ListThird Party Advisory
openwall.com / lists/oss-security/2021/05/04/7
Mailing ListThird Party Advisory
securityfocus.com / bid/108679
Broken LinkThird Party AdvisoryVDB Entry