Junglewise Threat Intelligence

CVE-2025-65318: Canary Mail protection mechanism failure in attachment handling

CVE-2025-65318 · Severity: critical · CVSS 9.1 · Published 2025-12-16

Executive brief

Canary Mail is an email client for Windows. A security flaw in how the application handles email attachments allows downloaded files to bypass standard Windows security warnings and protection features. This could allow a malicious document to automatically execute code or compromise a user's computer without the usual "Mark-of-the-Web" safety prompts that typically block untrusted files.

Technical details

Canary Mail (version 5.1.40 and below) fails to apply the 'Mark-of-the-Web' (MotW) NTFS Zone.Identifier stream when saving or opening email attachments via its 'Open with' or 'Save as' functionality. This omission causes Windows and third-party security software to treat these files as trusted local files rather than untrusted internet downloads. An attacker can exploit this by sending a specially crafted document (such as an RTF or DOCX using Remote Template Injection) that triggers secondary vulnerabilities, such as CVE-2017-11882 in Microsoft Office, without the user being stopped by Protected View or other MotW-dependent security sandboxes. The vulnerability is classified as a Protection Mechanism Failure (CWE-693).

Affected products

  • Canary Mail Canary Mail <= 5.1.40

Timeline

  • 2025-12-16: disclosed: Initial disclosure of CVE-2025-65318
  • 2025-12-16: advisory: NVD publication date

References