🔴 CVE-2025-42599

Critical stack-based buffer overflow in Active! mail 6 email server allows remote unauthenticated code execution. This vulnerability is actively exploited in the wild and listed in CISA KEV catalog.

← Back to Overview
HIGH_RISK
Risk Level
9.8
CVSS Score
NETWORK
Attack Vector
Initial Access
ATT&CK Tactic
T1190 — Exploit Public-Facing Application
ATT&CK Technique
HIGH
Deployment Risk
No
Ransomware

📋 Vulnerability Details

Data Source: CIRCL

Confidence: HIGH

Exploitation Method: DIRECT_NETWORK

CVE Published: 2025-04-18

Added to CISA KEV: 2025-04-28 10 DAYS BETWEEN CVE AND KEV

🎯 Recommendations:

🔍 Web Intelligence (Kagi · 2026-06-04)

CVE-2025-42599 is a critical stack-based buffer overflow vulnerability affecting Active! mail 6 (BuildInfo 6.60.05008561 and earlier), a product developed by QUALITIA CO., LTD. [1] [2]

Vulnerability Overview
  • Impact: Successful exploitation allows a remote, unauthenticated attacker to execute arbitrary code on the target system or cause a denial-of-service (DoS) condition [1] [6].
  • Attack Method: The vulnerability is triggered when the application processes a specially crafted request sent by an attacker [1].
  • Requirements: It is a remote, unauthenticated attack, meaning no user interaction is required for exploitation [1] [6].
Exploitation and Threat Landscape
  • Active Exploitation: As of June 2026, there is no public information indicating that this vulnerability has been added to the CISA Known Exploited Vulnerabilities (KEV) catalog, nor are there widespread reports of it being used in active ransomware campaigns or targeted attacks [3].
  • Proof-of-Concept/Tools: While the vulnerability was initially identified as a zero-day in April 2025 [5], security researchers have since developed detection templates (such as those for the Nuclei vulnerability scanner) to identify vulnerable instances [4] [7].
Mitigation and Status
  • Affected Versions: All versions of Active! mail 6 with BuildInfo 6.60.05008561 and earlier are affected [1].
  • Patch Status: Organizations using this software should verify their current BuildInfo version and apply updates provided by QUALITIA CO., LTD. to remediate the vulnerability. Users are advised to consult the official vendor advisories or the JVN (Japan Vulnerability Notes) entry for specific patch instructions [2].

Sources

  1. CVE-2025-42599 Detail - NVD

    Contains a stack-based buffer overflow vulnerability. Receiving a specially crafted request created and sent by a remote unauthenticated attacker may lead to ... CVE-2025-42599 is a critical stack-based buffer overflow vulnerability in Active! mail 6 BuildInfo: 6.60.05008561 and earlier. It may allo…

  2. JVN#22348866: Active! mail vulnerable to stack-based buffer overflow

    Active! mail provided by QUALITIA CO., LTD. contains a stack-based buffer overflow vulnerability (CWE-121). The developer states that attacks exploiting the ...

  3. Known Exploited Vulnerabilities Catalog | CISA

    For the benefit of the cybersecurity community and network defenders—and to help every organization better manage vulnerabilities and keep pace with threat.

  4. CVE-2025-42599 - Active! mail - Buffer Overflow #12963 - GitHub

    Description: Active! mail 6.60.05008561 and earlier contains a stack-based buffer overflow caused by processing specially crafted requests, ...

  5. Alert CVE-2025-42599 : An Active! Mail Zero-Day Remote Code ...

    Hunter (@HunterMapping). Alert CVE-2025-42599 : An Active! Mail Zero-Day Remote Code Execution https://t.co/0vAibFLG89 affects Active!…

  6. CVE-2025-42599 - Critical Stack Overflow in Active! mail 6 (BuildInfo ...

    *CVE-2025-42599* is a newly identified stack-based buffer overflow vulnerability directly impacting Active! mail 6, specifically versions with BuildInfo 6.60.05008561 and older. This flaw allows remote, unauthenticated attackers to execute arbitrary code or trigger a denial-of-service (DoS) simply b…

  7. feat: Implemented CVE-2025-42599 - Active! mail - Buffer Overflow

    This PR adds a detection template for CVE-2025-42599 affecting Active! Mail Server versions ≤ 6.60.05008561. The vulnerability is a stack-based ...