Impact
The vulnerability arises because the Windows installer of Progressive Robot Ltd’s hMailServer sets default permissions that allow the local Users group to read critical files and directories. This weakness corresponds to CWE‑276, which involves incorrect privilege assignment. An authenticated local user can therefore read stored mail messages, system logs, the internal database that contains account password hashes, and the hMailServer.INI configuration file. If the database password is exposed, a local account can unseal it using the machine’s DPAPI key, enabling an attacker to gain full control of an external database or extract credentials. This results in a loss of confidentiality for all stored emails and potentially full compromise of the mail server.
Affected Systems
Affected systems include all versions of hMailServer 6.0.0 through 6.3.5 on Windows produced by Progressive Robot Ltd. The same permission flaw exists in the Linux AppImage releases 6.3.0 through 6.3.5, where per‑user data folders are readable by other local users. The official remediation calls for upgrading to hMailServer 6.3.6, which adjusts folder and file permissions to restrict access to SYSTEM, Administrators, and the mail server service.
Risk and Exploitability
The CVSS score of 7.8 indicates a high impact vulnerability that requires local user privileges; the EPSS score is not available, so the likelihood of exploitation cannot be precisely measured, and the vulnerability is not currently listed in CISA’s KEV catalog. Attackers with legitimate local accounts can exploit this weakness by simply accessing the file system and reading protected data, so the attack vector is local authenticated user, and the exploitation is straightforward once the user can log in. Consequently, the risk is high and immediate remediation is recommended.
OpenCVE Enrichment