A newly disclosed high-severity vulnerability in the Exim mail transfer agent allows local attackers to exploit a directory traversal flaw to escalate privileges on affected systems. Tracked as EXIM-Security-2026-06-22.1 and assigned GCVE-25-2026-07-45-1, the issue impacts Exim versions from 4.88 through 4.99.4 and was publicly announced on July 22, 2026. Exim, widely deployed across Unix-like environments for handling email routing and delivery, is often configured with elevated privileges, making it a valuable target for post-compromise escalation. Exim Directory Traversal Vulnerability The vulnerability stems from improper handling of command-line arguments used during internal message queue processing. Specifically,...
Les hele artikkelen hos kilden.
Kommentarer (0)
Ingen kommentarer ennå. Bli den første til å kommentere!