Menu
  • Downloads
  • Knowledge Base
  • Documentation
  • Reputation
  • Email Security Tester
  • Downloads
  • Knowledge Base
  • Documentation
  • Reputation
  • Email Security Tester
home/Knowledge Base/Libraesva ESG/Security advisory: command injection vulnerability (CVE-2025-59689)
Popular searches:GDPR, ESG 5 migration guide, "How to configure Libraesva ESG for Microsoft 365"

Security advisory: command injection vulnerability (CVE-2025-59689)

8 views 0 September 19, 2025 rsa

Table of Contents

  • Description
  • Libraesva cloud customers
  • Libraesva on-premise customers
  • Vulnerability overview
    • Trigger mechanism
    • Impact
    • Known Exploitation
    • Remediation timeline
Print to PDF

Description

Libraesva ESG is affected by a command injection flaw that can be triggered by a malicious e-mail containing a specially crafted compressed attachment, allowing potential execution of arbitrary commands as a non-privileged user. This occurs due to an improper sanitization during the removal of active code from files contained in some compressed archive formats.

The vulnerability affects versions of Libraesva ESG starting from version 4.5.

For ESG 5.0 a fix has been released in 5.0.31
For ESG 5.1 a fix has been released in 5.1.20
For ESG 5.2 a fix has been released in 5.2.31
For ESG 5.4 a fix has been released in 5.4.8
For ESG 5.5. a fix has been released in 5.5.7

The fixes have been released through the automatic updates channel.

Versions below 5.0 are EOS and must be manually upgraded.

 

Libraesva cloud customers

All appliances in Libraesva cloud have been upgraded to the latest version containing the fix. No further action needed.

 

Libraesva on-premise customers

All on-premise appliances with versions 5.X have been automatically upgraded to the latest version containing the fix as confirmed by our telemetry data.

On-premise customers of version 5.X appliances can verify the current installed version in the admin dashboard.

On-premise customers with 4.X versions, which are in End Of Support, must manually upgrade to 5.x.

 

Vulnerability overview

Trigger mechanism

An attacker can exploit this flaw by sending an e‑mail that contains a specially crafted compressed archive. The vulnerability is only triggered with specific archive formats. Within the archive, the payload files are constructed to manipulate the application’s sanitization logic, exploiting an improper sanitization of input parameters.

Impact

Once the sanitization bypass is achieved, the attacker can execute arbitrary shell commands under a non‑privileged user account.

Known Exploitation

One confirmed incident of abuse has been identified. The threat actor is believed to be a foreign hostile state entity.

Remediation timeline

Discovery to Fix Deployment: 17 hours
Remediation Action: Libraesva released an emergency, automated patch to all ESG 5.x installations (both cloud and on‑prem).
Patch Contents:

  1. Core fix to correct the sanitization flaw.
  2. Automated scan for compromise indicators of compromise (IoCs).
  3. Self‑assessment module that runs on all affected appliances (cloud and on‑prem) to verify patch integrity and detect residual threats.

The single‑appliance focus underscores the precision of the threat actor (believed to be a foreign hostile state) and highlights the importance of rapid, comprehensive patch deployment.

 

Was this helpful?

Yes  No
Related Articles
  • Automatic mapping of Shared Mailbox in M365
  • Troubleshooting Outlook Add-in Authentication with Microsoft 365
  • Libraesva AI usage: technical implementation, governance, privacy and regulatory compliance
  • ESG API
  • Cluster Firewall ports requirements for workers (distributed setup)
  • Encryption at rest

Didn't find your answer? Contact Us

Popular Article
  • Security advisory: command injection vulnerability (CVE-2025-59689)
  • Automatic mapping of Shared Mailbox in M365
  • Migration process from UkCloud due to liquidation
  • Protocol number
  • Encryption at rest
Tag Cloud
active content blacklist Cluster Alert Cluster Error delisting delivery disk performance email esva file sandbox gdpr hypervisor ip address memory usage monitoring monitring performance privacy production quarantine disk quicksand rbl reputation retention time sandbox sanitize document security snmp template testing tnef uri sandbox url rewrite url sandbox winmail.dat zabbix

  Spam Checks Plugins

Scan results explained  

Products
  • Email Security Gateway
  • Email Archiving & Compliance
  • Phishing Awareness
Industry
  • SMB Companies
  • Large Companies
  • Education
  • MSP’s
Solutions
  • Microsoft 365
  • General Data Protection Regulation (GDPR)
  • Business Email Compromise
  • Migrate from Symantec
Resources
  • Email Security Tester
  • Company Website
  • Security Blog
  • Case Studies
  • Free Tech Webinars
Partners
  • Partner Portal
  • Become a Partner
  • Technology Alliances
Company
  • About Libraesva
  • Why Libraesva
  • News
  • Careers
  • Contact Us

LIBRAESVA SRL
Piazza Cermenati, 11
23900 Lecco - ITALY
VAT ID: 03442930131


LIBRAESVA LIMITED
Spaces, 83 Baker St
London W1U 6AG - United Kingdom
VAT ID: 274381685


LIBRAESVA INC
2608 2nd Ave, Suite 327
Seattle, WA 98121 - United States

  • (C) Libraesva 2024 - All rights reserved

We use cookies on our website to give you the most relevant experience by remembering your preferences and repeat visits. By clicking “Accept”, you consent to the use of ALL the cookies.
Cookie SettingsAccept
Manage consent

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. These cookies ensure basic functionalities and security features of the website, anonymously.
CookieDurationDescription
cookielawinfo-checkbox-analytics11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics".
cookielawinfo-checkbox-functional11 monthsThe cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional".
cookielawinfo-checkbox-necessary11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary".
cookielawinfo-checkbox-others11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other.
cookielawinfo-checkbox-performance11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance".
viewed_cookie_policy11 monthsThe cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data.
Functional
Functional cookies help to perform certain functionalities like sharing the content of the website on social media platforms, collect feedbacks, and other third-party features.
Performance
Performance cookies are used to understand and analyze the key performance indexes of the website which helps in delivering a better user experience for the visitors.
Analytics
Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics the number of visitors, bounce rate, traffic source, etc.
Advertisement
Advertisement cookies are used to provide visitors with relevant ads and marketing campaigns. These cookies track visitors across websites and collect information to provide customized ads.
Others
Other uncategorized cookies are those that are being analyzed and have not been classified into a category as yet.
SAVE & ACCEPT

WordPress Download Manager

WordPress Download Manager - Best Download Management Plugin

Popular searches:GDPR, ESG 5 migration guide, "How to configure Libraesva ESG for Microsoft 365"