Impact
The vulnerability is an improper link resolution flaw in administrative command-line operations of hMailServer, allowing a local attacker with service account privileges to write paths that follow junctions, mount points, or symbolic links to files outside the legitimate data directory. This flaw enables the attacker to overwrite logs, change certificates, or modify message files, thereby bypassing security boundaries. The flaw is a classic example of improper control of path names (CWE‑59).
Affected Systems
The vulnerability affects Progressive Robot Ltd’s hMailServer versions 6.3.4 and 6.3.5 on both Windows and Linux platforms. On Windows, the flaw is exploitable through installer, DBSetup, Control Panel, or administrative operations that run with elevated rights. On Linux, the flaw is exploitable during store‑maintenance or object‑storage operations that run as root and follow symbolic links planted by the service user. Version 6.3.6 eliminates the flaw by tightening path resolution and restricting file access to the data folder.
Risk and Exploitability
The CVSS score of 6.7 indicates a medium level severity, and the EPSS score is not available, but the absence from the KEV catalog suggests no known public exploitation. Attackers can elevate from the service account to administrator or root by executing privileged operations that follow malicious links. The vulnerability requires local code execution with service account rights, and the attacker must trigger one of the administrative commands that resolve external paths. Because the flaw is local, the risk to remote users is limited; however, compromised service accounts can lead to full control over the server.
OpenCVE Enrichment