
أداة لتوليد مؤشرات الكشف (Detection Artifact Generator) لثغرة 1day (Pre-Auth RCE) في SmarterMail
يحاول مولّد مؤشرات الكشف (Detection Artifact Generator) كتابة ملف .aspx في المجلد C:\Program Files (x86)\SmarterTools\SmarterMail\Service\App_Data (للإصدارات 94xx) أو في المجلد C:\Program Files (x86)\SmarterTools\SmarterMail\MRS\App_Data (للإصدار build 16). ولا يؤدي ذلك إلى تنفيذ الأوامر عن بُعد (Remote Code Execution)، بل يثبت فقط قابلية الاستغلال.
تم اختبار السكربت على:
لم يتم اختبار بعض الإصدارات الأقدم (مثل SmarterMail 15).
مثال لتشغيل الأداة ضد نسخة مستضعفة:
$ python3 .\watchTowr-vs-SmarterMail-CVE-2025-52691.py -H http://smartermail.lab:9998
__ ___ ___________
__ _ ______ _/ |__ ____ | |_\__ ____\____ _ ________
\ \/ \/ \__ \ ___/ ___\| | \| | / _ \ \/ \/ \_ __ \
\ / / __ \| | \ \___| Y | |( <_> \ / | | \/
\/\_/ (____ |__| \___ |___|__|__ | \__ / \/\_/ |__|
\/ \/ \/
watchTowr-vs-SmarterMail-CVE-2025-52691.py
(*) CVE-2025-52691 Detection Artifact Generator: SmarterMail Path Traversal Leading to Unauthenticated RCE
- Piotr (@chudyPB) and Sina Kheirkhah (@SinSinology) of watchTowr (@watchTowrcyber)
[+] VULNERABLE - file epoyn5_0.aspx got uploaded
مثال لتشغيل الأداة ضد نسخة مُصحَّحة:
$ python3 .\watchTowr-vs-SmarterMail-CVE-2025-52691.py -H http://smartermail.lab:9998
__ ___ ___________
__ _ ______ _/ |__ ____ | |_\__ ____\____ _ ________
\ \/ \/ \__ \ ___/ ___\| | \| | / _ \ \/ \/ \_ __ \
\ / / __ \| | \ \___| Y | |( <_> \ / | | \/
\/\_/ (____ |__| \___ |___|__|__ | \__ / \/\_/ |__|
\/ \/ \/
watchTowr-vs-SmarterMail-CVE-2025-52691.py
(*) CVE-2025-52691 Detection Artifact Generator: SmarterMail Path Traversal Leading to Unauthenticated RCE
- Piotr (@chudyPB) and Sina Kheirkhah (@SinSinology) of watchTowr (@watchTowrcyber)
[-] NOT VULNERABLE - patch applied (INVALID_GUID error message appeared)
يحاول هذا السكربت تحديد ما إذا كان SmarterMail عرضةً لثغرة CVE-2025-52691 (Pre-Auth RCE) أم لا.
< SmarterMail 9413
<= SmarterMail 16.3.6989.16341
لأحدث الأبحاث الأمنية، تابع فريق مختبرات watchTowr