CVE-2019-7214 is a critical vulnerability in SmarterTools SmarterMail 16.x (prior to Build 6985) that allows unauthenticated remote code execution as SYSTEM via insecure .NET deserialization on port 17001. The .NET remoting service exposed on this port accepted untrusted serialized data, enabling attackers to exploit the deserialization process using tools such as ExploitRemotingService and ysoserial.net to execute arbitrary commands on the server. The vulnerability was mitigated in Build 6985 by restricting port 17001 to local access only.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
4 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository contains a Python exploit script (CVE-2019-7214.py) and a README.md. The exploit targets SmarterMail (before build 6985) running on Windows, exploiting a .NET deserialization vulnerability (CVE-2019-7214) in the product's remoting endpoint. The script constructs a serialized .NET payload containing a base64-encoded PowerShell reverse shell command, which is sent over TCP to the target's vulnerable port (default 9998). If the exploit is successful, it provides the attacker with a remote PowerShell shell from the target system. The README provides configuration instructions, usage notes, and requirements. The exploit is operational and requires the attacker to set up a listener to receive the shell. The main fingerprintable endpoints are the target and attacker IP addresses and the use of /etc/hosts for hostname resolution.
This repository contains a single Metasploit module (smartermail_rce.rb) that exploits a .NET deserialization vulnerability (CVE-2019-7214) in SmarterTools SmarterMail (versions <= 16.x or builds < 6985) on Windows. The exploit targets three .NET remoting endpoints (/Servers, /Mail, /Spool) exposed on TCP port 17001. By sending a specially crafted serialized payload, an unauthenticated attacker can achieve remote code execution as NT AUTHORITY\SYSTEM. The module supports both direct command execution and staged payloads (e.g., Meterpreter reverse shell) using various stager flavors. The exploit is weaponized, highly configurable, and leverages Metasploit's payload and session management. The repository is structured as a single Ruby file compatible with the Metasploit framework, and all exploitation logic is contained within this file.
This repository contains a Python exploit for CVE-2019-7214, targeting SmarterMail versions prior to build 6985. The exploit leverages a .NET deserialization vulnerability in the .NET remoting endpoint (typically accessible at tcp://<rhost>:17001/Servers) to execute arbitrary code on the server. The main script, CVE-2019-7214.py, constructs a malicious serialized payload containing a base64-encoded PowerShell reverse shell command. When sent to the vulnerable endpoint, this payload causes the server to connect back to the attacker's machine, providing a PowerShell shell. The README provides usage instructions, including how to set up a netcat listener to receive the shell. The exploit is operational and requires the attacker to specify both the target and listener addresses. The repository is well-structured, with a single exploit script and a README for guidance.
This repository contains a working exploit for CVE-2019-7214, a remote code execution vulnerability in SmarterMail (versions before build 6985) due to unsafe .NET deserialization via a remoting endpoint. The main file, 'cve-2019-7214.py', is a Python script that crafts and sends a malicious serialized payload to the vulnerable .NET remoting service running on the target SmarterMail server. The payload is designed to execute a PowerShell reverse shell, connecting back to the attacker's machine and providing remote command execution. The script requires the attacker to specify the target server's IP and port, as well as the attacker's own IP and listening port for the reverse shell. The repository is structured simply, with a README describing the exploit and the Python exploit script itself. The exploit is operational and demonstrates a real-world attack scenario, but the payload is hardcoded and would require modification for different environments.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
1 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.