CVE-2025-52691
9.5 CISA KEVSmarterTools · SmarterMail
An unrestricted file upload vulnerability in SmarterTools SmarterMail allows unauthenticated attackers to achieve remote code execution on the mail server.
Executive summary
This critical vulnerability in SmarterTools SmarterMail is currently being exploited in the wild and allows unauthenticated attackers to execute arbitrary code on the server.
Vulnerability
The application fails to properly validate file types during upload, allowing an unauthenticated attacker to place malicious files in arbitrary locations on the server, which facilitates remote code execution.
Business impact
The exploitation of this vulnerability grants an attacker full control over the mail server, leading to a complete compromise of organizational communications, sensitive data exfiltration, and potential lateral movement into the internal network. With a CVSS score of 9.5, this flaw represents an extreme risk to business continuity and data integrity. The active exploitation of this vulnerability in the wild significantly elevates the urgency for immediate remediation.
Remediation
Immediate Action: Update SmarterMail to build 9413 or later immediately to patch the vulnerable file upload logic.
Proactive Monitoring: Review web server and application logs for suspicious file upload activity, particularly requests targeting directories outside the intended upload path or files with executable extensions.
Compensating Controls: Deploy a Web Application Firewall (WAF) with rules configured to block file uploads containing suspicious headers or non-standard file extensions until the update is applied.
Exploitation status
Public Exploit Available: Yes, a Metasploit module exists and multiple public proof-of-concept repositories are available on GitHub.
Analyst recommendation
Given the confirmed active exploitation and the severity of the potential impact, organizations must prioritize patching SmarterMail to build 9413 without delay. Failure to address this vulnerability exposes the environment to immediate remote compromise. If patching is not immediately feasible, consider isolating the mail server from the public internet until the update is deployed.
More SmarterTools CVEs
History
- Disclosed CVE record published
- Published in the daily brief critical section
- Published in the daily brief critical section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Published in the daily brief kev section
- Analyst report written
- Fix documented per CVE record
Sources
Originally found and disclosed by Chua Meng Han, per the CVE Program record.