
PoC for CVE-2019-10149, this vulnerability could be xploited betwen 4-87 to 4.91 version of Exim server.
MNEMO-CERT has developed a PoC that allows executing commands with elevated privileges by exploiting the vulnerability CVE-2019-10149, which affects different versions of Exim (4.87 - 4.91).
To perform local exploitation of this vulnerability it is necessary to define the command to be executed. On the other hand, for the remote case only the scenario in which Exim does not use the ACL "verify= recipient" was considered, for which in addition to the command the IP address and port of the service must be indicated.
MNEMO-CERT has developed this PoC solely for educational purposes and for the execution of ethical tests that allow recreating the failure described in CVE-2019-10149. This PoC must be used only in controlled environments or with the necessary authorizations.
The exploitation of existing vulnerabilities in systems without proper consent may constitute a crime, depending on local laws. MNEMO-CERT is not responsible for the misuse of this PoC.