CVE-2025-42599
KEVlargeUnauthenticated RCE via Stack-Based Buffer Overflow in Qualitia Active! mail 6
CISA: Qualitia Active! Mail Stack-Based Buffer Overflow Vulnerability
Qualitia Active! mail 6 (BuildInfo 6.60.05008561 and earlier) contains a stack-based buffer overflow (CWE-121) that is triggered when the webmail server processes a single specially crafted network request, with no authentication or user interaction required. A remote unauthenticated attacker who sends such a request can execute arbitrary code on the server or crash the service, causing a denial-of-service condition. With a CVSS 3.1 score of 9.8 (AV:N/AC:L/PR:N/UI:N, high impact on confidentiality, integrity, and availability), any internet-exposed deployment is at critical risk; the product is a webmail platform widely deployed by Japanese enterprises, universities, and government organizations. CISA added the flaw to the Known Exploited Vulnerabilities catalog on 2025-04-28, confirming exploitation in the wild, though no public proof-of-concept is known and ransomware use has not been reported. Organizations running affected builds should treat their webmail servers as likely targets and patch per vendor guidance immediately.
What to do: Upgrade Active! mail 6 to a BuildInfo later than 6.60.05008561, following Qualitia's advisory (JPCERT is the assigning CNA, so its alert should be used as the authoritative update reference). Until patched, restrict internet access to the webmail interface via IP allow-listing or VPN and review server logs for exploitation attempts, since in-the-wild exploitation is confirmed. US federal agencies must apply the required mitigations per vendor instructions and BOD 22-01 timelines, or discontinue use of the product if mitigations are unavailable.
| Qualitia Active! mail 6 | BuildInfo 6.60.05008561 and earlier |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Active! mail 6 BuildInfo: 6.60.05008561 and earlier contains a stack-based buffer overflow vulnerability. Receiving a specially crafted request created and sent by a remote unauthenticated attacker may lead to arbitrary code execution and/or a denial-of-service (DoS) condition.
- Affected
- Qualitia Active! Mail
- Required action
- Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- qualitia
- Products
- active\! mail
- Weakness
- CWE-121
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H