CVE-2020-28008 is a privilege escalation vulnerability affecting Exim versions prior to 4.94.2. An attacker with local access can exploit Exim's root privileges in the spool directory to craft a recipient address in a spool header file, leading to arbitrary command execution. This vulnerability has a CVSS score of 7.8 (High), indicating a significant impact with high confidentiality, integrity, and availability compromise. While not listed in CISA's KEV catalog, it has garnered community discussion and media coverage, including a BleepingComputer article on "21Nails" Exim bugs. There is no public exploit code available in Metasploit, Nuclei, or ExploitDB.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 4.00, < 4.94.2CPE matchmatch criteria | cpe:2.3:a:exim:exim:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.