Millions of Exim servers vulnerable to root-granting exploit
Summary
Millions of Exim servers are vulnerable to a security bug that when exploited can grant attackers the ability to run malicious code with root privileges. The issue was reported in early July by a security researcher named Zerons, and has been patched in the utmost secrecy by the Exim team. This mitigation is not recommended for Exim owners living in the EU, since this may expose their companies to data leaks, and the subsequent GDPR fines. Furthermore, Exim instances that ship with cPanel, a popular web hosting software, also support TLS by default. The "Return of the WIZard" vulnerability came under active exploitation within a week after public disclosure, and someone crafted an Azure worm three days after that, forcing Microsoft to send out a security alert to all customers.