CVE-2019-7214

CRITICAL

SmarterTools SmarterMail less than build 6985 - .NET Deserialization Remote Code Execution

Title source: metasploit
STIX 2.1

Exploitation Summary

EIP tracks 6 public exploits for CVE-2019-7214. PoCs published by 1F98D, Drew-Alleman, andyfeili, including Metasploit module exploits/windows/http/smartermail_rce.

AI-analyzed exploit summary This exploit targets a .NET deserialization vulnerability in SmarterMail before build 6985. It sends a crafted payload to a .NET remoting endpoint to achieve remote code execution via a PowerShell reverse shell.

Description

SmarterTools SmarterMail 16.x before build 6985 allows deserialization of untrusted data. An unauthenticated attacker could run commands on the server when port 17001 was remotely accessible. This port is not accessible remotely by default after applying the Build 6985 patch.

Exploits (6)

exploitdb WORKING POC
by 1F98D · pythonremotewindows
https://www.exploit-db.com/exploits/49216

This exploit targets a .NET deserialization vulnerability in SmarterMail before build 6985. It sends a crafted payload to a .NET remoting endpoint to achieve remote code execution via a PowerShell reverse shell.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: SmarterMail before build 6985
No auth needed
Prerequisites: Network access to the target's .NET remoting endpoint (port 17001) · Target must be running a vulnerable version of SmarterMail
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC 3 stars
by Drew-Alleman · poc
https://github.com/Drew-Alleman/CVE-2019-7214

This is a Python-based exploit for CVE-2019-7214, targeting a .NET deserialization vulnerability in SmarterMail before build 6985. It sends a malicious payload to achieve remote code execution via a reverse shell.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: SmarterMail < Build 6985
No auth needed
Prerequisites: Network access to the target SmarterMail server · Target must be running a vulnerable version of SmarterMail
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC 1 stars
by andyfeili · poc
https://github.com/andyfeili/-CVE-2019-7214

This PoC exploits a .NET deserialization vulnerability in SmarterMail before build 6985 to achieve remote code execution. It sends a crafted payload to a .NET remoting endpoint, triggering arbitrary command execution via a PowerShell reverse shell.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: SmarterMail before build 6985
No auth needed
Prerequisites: Network access to the target's .NET remoting endpoint (port 17001) · Target running SmarterMail before build 6985
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC 1 stars
by devzspy · poc
https://github.com/devzspy/CVE-2019-7214

This PoC exploits a .NET deserialization vulnerability in SmarterMail before build 6985 to achieve remote code execution. It sends a crafted payload to a .NET remoting endpoint, triggering arbitrary command execution via a PowerShell reverse shell.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: SmarterMail < Build 6985
No auth needed
Prerequisites: Network access to the target's .NET remoting endpoint (port 17001) · Target running SmarterMail < Build 6985
devstral-2 · analyzed Feb 16, 2026 Full analysis →
nomisec WORKING POC
by ElusiveHacker · poc
https://github.com/ElusiveHacker/CVE-2019-7214

This is a functional exploit for CVE-2019-7214, targeting a .NET deserialization vulnerability in SmarterMail before build 6985. It sends a serialized payload to execute a PowerShell reverse shell.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: SmarterMail before build 6985
No auth needed
Prerequisites: Target must be running SmarterMail before build 6985 · Network access to the target's .NET remoting endpoint · Attacker must have a listener set up for the reverse shell
devstral-2 · analyzed Feb 16, 2026 Full analysis →
metasploit WORKING POC EXCELLENT
by Soroush Dalili, 1F98D, Ismail E. Dawoodjee · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/http/smartermail_rce.rb

This Metasploit module exploits a .NET deserialization vulnerability (CVE-2019-7214) in SmarterTools SmarterMail versions <= 16.x or builds < 6985. It sends a malicious serialized payload to one of three exposed .NET remoting endpoints on port 17001, achieving unauthenticated remote code execution as SYSTEM.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: SmarterTools SmarterMail <= 16.x or build < 6985
No auth needed
Prerequisites: Network access to TCP port 17001 · Vulnerable SmarterMail version/build
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Scores

CVSS v3 9.8
EPSS 0.8332
EPSS Percentile 99.6%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-502
Status published
Products (1)
smartertools/smartermail 16.0.6345 - 16.3.6985
Published Apr 24, 2019
Tracked Since Feb 18, 2026