Executive brief
Blue Mail, a popular email client, fails to properly tag downloaded attachments with security metadata known as 'Mark-of-the-Web'. This allows malicious files to bypass standard Windows security warnings and protection mechanisms that usually block suspicious downloads. If a user opens a specially crafted attachment, an attacker could potentially gain control of the computer or execute unauthorized commands.
Technical details
Blue Mail versions 1.140.103 and below suffer from a protection mechanism failure (CWE-693) in the attachment interaction functionality. When a user saves or opens an attachment, the application fails to apply the Zone.Identifier NTFS alternate data stream (Mark-of-the-Web). This omission allows downloaded files to bypass Windows security features like SmartScreen and Office Protected View. Attackers can leverage this to deliver malicious documents (e.g., RTF or DOCX files exploiting CVE-2017-11882) that execute immediately upon opening without the standard OS-level security warnings that would otherwise alert the user.
Affected products
- Blix Blue Mail 1.140.103 and below
Timeline
- 2025-12-16: advisory: Initial NVD publication
- 2025-12-17: other: CISA-ADP enrichment and CVSS scoring added