Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-9crh-xp9v-855p

Опубликовано: 19 дек. 2025
Источник: github
Github: Не прошло ревью
CVSS4: 8.5
CVSS3: 8.4

Описание

AspEmail 5.6.0.2 contains a binary permission vulnerability that allows local users to escalate privileges through the Persits Software EmailAgent service. Attackers can exploit full write permissions in the BIN directory to replace the service executable and gain elevated system access.

AspEmail 5.6.0.2 contains a binary permission vulnerability that allows local users to escalate privileges through the Persits Software EmailAgent service. Attackers can exploit full write permissions in the BIN directory to replace the service executable and gain elevated system access.

EPSS

Процентиль: 2%
0.00015
Низкий

8.5 High

CVSS4

8.4 High

CVSS3

Дефекты

CWE-732

Связанные уязвимости

CVSS3: 8.4
nvd
около 2 месяцев назад

AspEmail 5.6.0.2 contains a binary permission vulnerability that allows local users to escalate privileges through the Persits Software EmailAgent service. Attackers can exploit full write permissions in the BIN directory to replace the service executable and gain elevated system access.

EPSS

Процентиль: 2%
0.00015
Низкий

8.5 High

CVSS4

8.4 High

CVSS3

Дефекты

CWE-732