NA

CVE-2024-28589

Published: 03/04/2024 Updated: 03/04/2024

Vulnerability Summary

An issue exists in Axigen Mail Server for Windows versions 10.5.18 and before, allows local low-privileged malicious users to execute arbitrary code and escalate privileges via insecure DLL loading from a world-writable directory during service initialization.

Github Repositories

Local Privilege Escalation Vulnerability on Axigen for Windows

CVE-2024-28589 A vulnerability has been discovered in Axigen Mail Server for Windows, affecting all versions up to 10518, which allows for local privilege escalation Description: The Axigen Mail Server was found to be vulnerable to a local privilege escalation due to insecure DLL loading from a world-writable directory During the service initiation of "Axigen Mail Serv