PatchSiren cyber security CVE debrief
CVE-2010-4345 Exim CVE debrief
CVE-2010-4345 is an Exim privilege escalation vulnerability that CISA has listed in its Known Exploited Vulnerabilities catalog. The KEV entry indicates this issue is considered actively exploited or of confirmed exploitation concern, so Exim deployments should be treated as urgent patch candidates. CISA’s guidance is to apply updates per vendor instructions.
- Vendor
- Exim
- Product
- Exim
- CVSS
- Unknown
- CISA KEV
- Listed
- Original CVE published
- 2022-03-25
- Original CVE updated
- 2022-03-25
- Advisory published
- 2022-03-25
- Advisory updated
- 2022-03-25
Who should care
System administrators, mail server operators, and security teams responsible for Exim deployments should prioritize this vulnerability, especially on internet-facing or production mail systems.
Technical summary
The official sources identify CVE-2010-4345 as a privilege escalation issue affecting Exim. CISA added it to the Known Exploited Vulnerabilities catalog on 2022-03-25 and set a remediation due date of 2022-04-15. The available corpus does not provide exploit mechanics or affected version details, so defensive handling should rely on the vendor’s update guidance and the official CVE/NVD records.
Defensive priority
Urgent. Because this CVE appears in CISA’s KEV catalog, it should be prioritized ahead of routine maintenance, with patching and validation expedited for any systems running Exim.
Recommended defensive actions
- Inventory all systems running Exim and confirm where the software is installed.
- Review the official CVE and NVD records together with vendor instructions for affected versions and remediation steps.
- Apply the vendor-recommended updates or mitigations as soon as possible.
- Prioritize exposed, production, and high-value mail systems first.
- Validate that remediation succeeded and document the patch status for compliance tracking.
Evidence notes
This debrief is intentionally limited to the supplied corpus and official links. The strongest evidence is CISA’s KEV listing, which names Exim and classifies CVE-2010-4345 as a privilege escalation vulnerability with a remediation due date. The CVE and NVD links corroborate the identifier and vulnerability record, but the corpus does not include exploit details, impact depth, or version-specific applicability.
Official resources
-
CVE-2010-4345 CVE record
CVE.org
-
CVE-2010-4345 NVD detail
NVD
-
CISA Known Exploited Vulnerabilities catalog
CISA - Apply updates per vendor instructions.
-
Source item URL
cisa_kev
CISA added CVE-2010-4345 to the Known Exploited Vulnerabilities catalog on 2022-03-25 and set a remediation due date of 2022-04-15.