SmarterMail 预认证 RCE 1day 检测产物生成工具
检测产物生成工具尝试将 .aspx 文件写入 C:\Program Files (x86)\SmarterTools\SmarterMail\Service\App_Data 目录(94xx 版本)或 C:\Program Files (x86)\SmarterTools\SmarterMail\MRS\App_Data 目录(16 版本)。这不会导致远程代码执行,仅用于证明漏洞可利用性。
该脚本已在以下环境测试:
部分更旧的版本(如 SmarterMail 15)未经过测试。
针对存在漏洞的实例运行示例:
$ python3 .\watchTowr-vs-SmarterMail-CVE-2025-52691.py -H http://smartermail.lab:9998
__ ___ ___________
__ _ ______ _/ |__ ____ | |_\__ ____\____ _ ________
\ \/ \/ \__ \ ___/ ___\| | \| | / _ \ \/ \/ \_ __ \
\ / / __ \| | \ \___| Y | |( <_> \ / | | \/
\/\_/ (____ |__| \___ |___|__|__ | \__ / \/\_/ |__|
\/ \/ \/
watchTowr-vs-SmarterMail-CVE-2025-52691.py
(*) CVE-2025-52691 Detection Artifact Generator: SmarterMail Path Traversal Leading to Unauthenticated RCE
- Piotr (@chudyPB) and Sina Kheirkhah (@SinSinology) of watchTowr (@watchTowrcyber)
[+] VULNERABLE - file epoyn5_0.aspx got uploaded
针对已修补实例运行示例:
$ python3 .\watchTowr-vs-SmarterMail-CVE-2025-52691.py -H http://smartermail.lab:9998
__ ___ ___________
__ _ ______ _/ |__ ____ | |_\__ ____\____ _ ________
\ \/ \/ \__ \ ___/ ___\| | \| | / _ \ \/ \/ \_ __ \
\ / / __ \| | \ \___| Y | |( <_> \ / | | \/
\/\_/ (____ |__| \___ |___|__|__ | \__ / \/\_/ |__|
\/ \/ \/
watchTowr-vs-SmarterMail-CVE-2025-52691.py
(*) CVE-2025-52691 Detection Artifact Generator: SmarterMail Path Traversal Leading to Unauthenticated RCE
- Piotr (@chudyPB) and Sina Kheirkhah (@SinSinology) of watchTowr (@watchTowrcyber)
[-] NOT VULNERABLE - patch applied (INVALID_GUID error message appeared)
该脚本用于检测 SmarterMail 是否存在 CVE-2025-52691 预认证 RCE 漏洞。
< SmarterMail 9413
<= SmarterMail 16.3.6989.16341
获取最新安全研究,请关注 watchTowr 实验室团队