CVE-2019-10149
Exim Mail Transfer Agent (MTA) Improper Input Validation
- Published
- Jun 5, 2019
- Updated
- Oct 21, 2025
- Assigning CNA
- redhat
- Evidence observed
- Jun 5, 2019
Primary CVSS
nvd · CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HHigh · next 30 days
- Percentile
- 100.0%
- Model date
- Sep 21, 2026
EPSS is a statistical estimate, not a certainty or a measure of impact. Combine it with CVSS, KEV status, exposure and your environment.
CISA Known Exploited
This CVE appears in the CISA Known Exploited Vulnerabilities catalog.
Summary
A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message() function in /src/deliver.c may lead to remote command execution.
Sources
21- exploitsExploit
Public exploit repository covering local privilege escalation, buffer overflows, and database exploits across Linux, Solaris, AIX, OpenBSD, Zyxel, Oracle, and MySQL.
- CVE-2019-10149-Exim4-RCEExploit
Local privilege escalation exploit for Exim 4.87-4.91 (CVE-2019-10149). Delivers a setuid root shell helper via crafted SMTP commands, enabling privilege escalation from standard user to root.
- CVE-2019-10149Exploit
CVE-2019-10149 : A flaw was found in Exim versions 4.87 to 4.91 (inclusive). Improper validation of recipient address in deliver_message() function in /src/deliver.c may lead to remote command execution.
Responsible use
Use vulnerability information only on systems you own or are authorized to test. Kitploit links to public research metadata and does not store exploit code or malicious payloads.