Impact
Missing authorization on the COM objects of hMailServer 6.0.0 through 6.3.5 allows a local interactive user without hMailServer credentials to activate those objects and read or write any file that the service account can access. The exposed Attachments.Add, Attachment.SaveAs, and Message.Save methods perform no authentication checks, enabling the user to read arbitrary files, overwrite existing files, or create new ones on the server. Because the service runs under its service account and does not impersonate the caller, the attacker can write arbitrary data, potentially leading to code execution if that account has SYSTEM privileges, and can queue outbound mail from any address, bypassing SMTP checks.
Affected Systems
The vulnerability impacts Progressive Robot Ltd's hMailServer product version 6.0.0 through 6.3.5 on Windows operating systems. The affected components are the server's COM classes registered on the Windows machine, which are used by the hMailServer service and do not enforce DCOM access or launch permissions. Versions 6.3.6 and later include protection against this issue.
Risk and Exploitability
The CVSS v3.1 score of 7.8 indicates high severity, and the lack of an EPSS score shows limited public exploitation data at this time. The vulnerability is not listed in CISA's KEV catalog, access, such as console or Remote Desktop logon. An attacker simply opens a local PowerShell or VBScript session, activates a COM object, and can read or overwrite files, queue mails, or create fetch jobs, thereby compromising confidentiality, integrity, or the ability to send spam. If the service account is running as SYSTEM, the impact elevates to local privilege escalation and full code execution on the host.
OpenCVE Enrichment