CVE-2025-61084: Input Validation
MDaemon Mail Server 23.5.2 validates SPF, DKIM, and DMARC using the email enclosed in angle brackets (<>) in the From: header of SMTP DATA. An attacker can craft a From: header with multiple invisible Unicode thin spaces to display a spoofed sender while passing validation, allowing email spoofing even when anti-spoofing protections are in place. NOTE: this is disputed by the Supplier because UI spoofing occurs in a client, not in a server such as MDaemon's product or any other server implementation. Also, if a client without its own spoofing protection must be used, the Header Screening feature in MDaemon's product can be employed to mitigate the client-side vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-61084?
CVE-2025-61084 is considered a high severity vulnerability due to its potential for email spoofing.
How do I fix CVE-2025-61084?
To fix CVE-2025-61084, update your MDaemon Mail Server to the latest version that addresses this vulnerability.
What types of attacks can CVE-2025-61084 facilitate?
CVE-2025-61084 can facilitate email spoofing attacks, allowing attackers to impersonate legitimate senders.
Which versions of MDaemon Mail Server are affected by CVE-2025-61084?
MDaemon Mail Server version 23.5.2 is affected by CVE-2025-61084, so users of this version should take immediate action.
How can I confirm if my mailbox is being spoofed due to CVE-2025-61084?
You can check email headers for unusual characters or formatting that may indicate spoofing as a result of CVE-2025-61084.