CVE-2025-59689 – Command Injection – Libraesva Email Security Gateway

ISGroup Cybersecurity

Libraesva Email Security Gateway (ESG) is an email security solution used by organizations to filter spam, block phishing attempts, and provide multi-layered protection against email-borne threats. The vulnerability identified as CVE-2025-59689 allows an attacker to execute arbitrary shell commands remotely as an unprivileged user, without the need for authentication.

The vulnerability affects Libraesva ESG versions 4.5 through 5.5.x (prior to the corrective versions). Since there have been confirmed cases of active exploitation and the vulnerability has been added to CISA’s Known Exploited Vulnerabilities (KEV) catalog, it is critical to apply the available patches immediately.

Date2025-10-07 13:30:31

Technical Summary

The vulnerability is a command injection triggered by a specially crafted compressed email attachment. The root cause is “inadequate sanitization during the removal of active code from files contained within certain compressed archive formats.”

The ESG device inspects and processes compressed archives (ZIP/tar/gz and similar) embedded in incoming emails to remove or neutralize active content (scripts, executables, etc.). During this sanitization pipeline, the product accepted attacker-controlled data from the archive (file names and/or file contents) and used them in a context where shell interpolation or an insecure external call occurred, thereby allowing the attacker to inject commands that the ESG process executed as an unprivileged local user.

Recommendations

  1. Apply the patch immediately: Below are the corrective versions corresponding to each ESG version:
ESG Version Fixed Version
5.05.0.31
5.15.1.20
5.25.2.31
5.35.3.16
5.45.4.8
5.55.5.7
  1. Scan for IoCs: The patch includes an automatic scan for Indicators of Compromise (IoCs) and a self-verification module that runs on all affected devices to verify the integrity of the patch and detect any residual threats.

  2. Monitoring: Analyze email gateway logs for suspicious compressed attachments.

Protect your organisation with Threat Intelligence and Digital Risk Protection.

Choose ISGroup for a practical, tailored engagement:

  • A focused assessment of your environment and requirements
  • Clear findings with a prioritised, actionable roadmap
  • Direct support from experienced specialists through remediation and implementation
Talk to an expert