Impact
The Linux live‑update apply helper (hmailserver‑update) runs as root based on a request file written by the unprivileged hmailserver service account, and uses that file to determine which program to run for signature verification and which systemd unit to stop before reading the service account's files. An attacker who can execute code as the hmailserver account, for example through another flaw in the mail server, can therefore obtain arbitrary root privileges by crafting a malicious request, causing the helper to execute attacker‑supplied code as root. This privilege escalation can be applied to any Linux installation where the live‑update path unit is active – the default for the project's .deb and .rpm packages – and to AppImage installations that run under that unit.
Affected Systems
The vulnerability affects Progressive Robot's hMailServer versions 6.3.4 and 6.3.5 running on Linux. The flaw is mitigated in hMailServer 6.3.6, where the helper limits input to its own root‑owned command line, refuses unnamed AppImage requests, and ensures the server is stopped before processing, verifying, and installing only locally‑created, root‑readable copies. Users of the default package managers (apt or dnf) or of AppImage installations that rely on the live‑update path unit are therefore at risk if they remain on the affected versions.
Risk and Exploitability
The CVSS score of 7.8 denotes a high severity vulnerability, and while the EPSS score is not available, the lack of a KEV listing suggests limited public exploitation so far. However, the attack requires local code execution as the hmailserver service account, which can be achieved via other, potentially already exploited, flaws. Once such foothold is gained, the untrusted request file allows the helper to run arbitrary payloads as root, giving full system control. The risk is therefore high for affected deployments that have not applied the latest patch or disabled the live‑update path unit.
OpenCVE Enrichment