Junglewise Threat Intelligence

CVE-2025-42599: Qualitia Active! Mail Stack-Based Buffer Overflow Vulnerability

CVE-2025-42599 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2025-04-28

Executive brief

Qualitia Active! mail 6 contains a stack-based buffer overflow vulnerability (CWE-121) due to improper handling of specially crafted requests. A remote, unauthenticated attacker can exploit this to execute arbitrary code or cause a denial-of-service (DoS) condition.

Affected products

  • Qualitia Active! mail 6 BuildInfo: 6.60.05008561 and earlier

Timeline

  • 2025-04-18: disclosed: Initial disclosure by JPCERT/CC and vendor advisory published.
  • 2025-04-28: kev added: Added to CISA Known Exploited Vulnerabilities (KEV) catalog.