Executive brief
Canary Mail is an email client for Windows. A security flaw in how the application handles email attachments allows downloaded files to bypass standard Windows security warnings and protection features. This could allow a malicious document to automatically execute code or compromise a user's computer without the usual "Mark-of-the-Web" safety prompts that typically block untrusted files.
Technical details
Canary Mail (version 5.1.40 and below) fails to apply the 'Mark-of-the-Web' (MotW) NTFS Zone.Identifier stream when saving or opening email attachments via its 'Open with' or 'Save as' functionality. This omission causes Windows and third-party security software to treat these files as trusted local files rather than untrusted internet downloads. An attacker can exploit this by sending a specially crafted document (such as an RTF or DOCX using Remote Template Injection) that triggers secondary vulnerabilities, such as CVE-2017-11882 in Microsoft Office, without the user being stopped by Protected View or other MotW-dependent security sandboxes. The vulnerability is classified as a Protection Mechanism Failure (CWE-693).
Affected products
- Canary Mail Canary Mail <= 5.1.40
Timeline
- 2025-12-16: disclosed: Initial disclosure of CVE-2025-65318
- 2025-12-16: advisory: NVD publication date