Some of the vulnerabilities can be chained together to obtain a full remote unauthenticated code execution and gain root privileges on the Exim server. Exim has released a security update to address multiple vulnerabilities in Exim versions prior to 4.94.2.2. Qualys recommends security teams to apply patches for these vulnerabilities as soon as possible. Last year, the vulnerability was a target of Russian cyber actors formally known as the sandworm team. The Qualys Research Team engaged in a thorough code audit of Exim and discovered 21 unique vulnerabilities.”]

