PETALING JAYA: Some 5,500 email servers in Malaysia are at risk of being hacked due to a vulnerability among servers without up-to-date software, according to a Malaysian cybersecurity company.
The major vulnerability (CVE-2019-10149) was found on Exim, a Message Transfer Agent (MTA) software used by more than half (57%) of email servers around the world, said Vigilant Asia Sdn Bhd’s threat intelligence team.
First discovered by US cybersecurity firm Qualys, the flaw allows local or remote attackers to send malicious emails to vulnerable Exim servers – using version 4.87 to 4.91 of the software – and run malicious commands to take over the system, allowing them to access critical infrastructure of an organisation through that server.
Malaysia Computer Emergency Response Team (MyCERT), a department under CyberSecurity Malay-sia, issued an advisory about the Exim Vulnerability on June 14, recommending users and administrators of affected products to update to version 4.92 immediately.
CyberSecurity Malaysia senior vice-president for cybersecurity responsive services Dr Aswami Ariffin explained that MTA software was like mailmen, transferring email messages from sender to receiver.
“A hacked server is just like our postman being compromised: allowing anything to be posted to our address, and in this case the intent is malicious,” he said.
Though a patch was released for the vulnerability on Feb 10, Vigilant Asia found that of the more than 7,700 Exim servers that are reachable from public Internet in Malaysia, more than 5,500 servers have not updated to the latest version of Exim (4.92).
Asked if Malaysian servers had been hacked, the team could not confirm this. Based on their intel and public reports, there had been attacks by at least two hacker groups, with one operating from public Internet and another using a server located in the Dark Web.
Already a subscriber? Log in
Get 20% OFF The Star Digital Access
Cancel anytime. Ad-free. Unlimited access with perks.
