An Active! Mail zero-day remote code execution vulnerability is actively exploited in attacks on large organizations in Japan. Active! mail is a web-based email client developed initially by TransWARE and later acquired by Qualitia, both Japanese companies. While it's not widely used worldwide like Gmail or Outlook, Active! is often used as a groupware component in Japanese-language environments of large corporations, universities, government agencies, and banks. According to the vendor, Active! is used in over 2,250 organizations, boasting over 11,000,000 accounts, making it a significant player in the country's business webmail market. Late last week, Qualitia released a security bulletin about a stack-based buffer overflow vulnerability tracked under CVE-2025-42599 (CVSS v3 score: 9.8, "critical") impacting all versions of Active! up to and including 'BuildInfo: 6.60.05008561' on all supported OS platforms. "If a maliciously crafted request is sent by a remote third party, there is a possibility of arbitrary code execution or a denial-of-service (DoS) condition being triggered," reads the bulletin. Although Qualitia mentions investigating whether the flaw has been exploited, Japan's CERT has confirmed its active exploitation status, urging all users to update to Active! Mail 6 BuildInfo: 6.60.06008562 as soon as possible. Japanese web hosting and IT services (SMB) provider Kagoya Japan reported several external attacks over the weekend, prompting it to temporarily suspend...
Active! Mail RCE flaw exploited in attacks on Japanese orgs
BleepingComputer
·Bill Toulas
·Published Apr 22, 2025
·Updated
Affected Software
2 affected components
Qualitia Active! Mail=6.60.05008561
Qualitia Active! Mail
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses a zero-day remote code execution vulnerability in the Active! Mail software that is being actively exploited in cyber attacks targeting organizations in Japan.
2
What security implications are discussed?
The article details the risks associated with the exploitation of the Active! Mail vulnerability, which could allow attackers to execute remote code and potentially gain unauthorized access to sensitive information.
3
What products or software are affected?
The affected product is Qualitia Active! Mail, specifically version 6.60.05008561.
4
Who developed Active! Mail?
Active! Mail was initially developed by TransWARE and was later acquired by Qualitia.
5
How severe is the vulnerability reported in the article?
The vulnerability is classified as a zero-day exploit, indicating a high severity due to its active exploitation before a fix has been released.