ZeroHour

CVE-2025-42599

KEVlarge

Unauthenticated RCE via Stack-Based Buffer Overflow in Qualitia Active! mail 6

CISA: Qualitia Active! Mail Stack-Based Buffer Overflow Vulnerability

CVSS 3.1
9.8 critical
EPSS
3%p88
Published
()
KEV added
AI analysis

Qualitia Active! mail 6 (BuildInfo 6.60.05008561 and earlier) contains a stack-based buffer overflow (CWE-121) that is triggered when the webmail server processes a single specially crafted network request, with no authentication or user interaction required. A remote unauthenticated attacker who sends such a request can execute arbitrary code on the server or crash the service, causing a denial-of-service condition. With a CVSS 3.1 score of 9.8 (AV:N/AC:L/PR:N/UI:N, high impact on confidentiality, integrity, and availability), any internet-exposed deployment is at critical risk; the product is a webmail platform widely deployed by Japanese enterprises, universities, and government organizations. CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2025-04-28, confirming exploitation in the wild, though no public proof-of-concept is known and ransomware use has not been reported. Organizations running affected builds should treat their webmail servers as likely targets and patch per vendor guidance immediately.

What to do: Upgrade Active! mail 6 to a BuildInfo later than 6.60.05008561, following Qualitia's advisory (JPCERT is the assigning CNA, so its alert should be used as the authoritative update reference). Until patched, restrict internet access to the webmail interface via IP allow-listing or VPN and review server logs for exploitation attempts, since in-the-wild exploitation is confirmed. US federal agencies must apply the required mitigations per vendor instructions and BOD 22-01 timelines, or discontinue use of the product if mitigations are unavailable.

Affected
Qualitia Active! mail 6BuildInfo 6.60.05008561 and earlier
Estimated exposure
largelikely on the order of 100,000+ users (mailboxes) across a thousand-plus Japanese organizations, with thousands of internet-exposed webmail servers — Active! mail is a long-established Japanese webmail product deployed at Japanese enterprises, universities, and municipal governments; this order-of-magnitude estimate is derived from that adoption pattern and the fact that webmail…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Active! mail 6 BuildInfo: 6.60.05008561 and earlier contains a stack-based buffer overflow vulnerability. Receiving a specially crafted request created and sent by a remote unauthenticated attacker may lead to arbitrary code execution and/or a denial-of-service (DoS) condition.

CISA Known Exploited Vulnerability
Affected
Qualitia Active! Mail
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
qualitia
Products
active\! mail
Weakness
CWE-121
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news