Sceawere

Vulnerability Detail

CVE-2026-104660UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

hMailServer Insecure COM Authorization

Vulnerability Metadata

Severity
High
Score / CVSS
7.8
Creation Date
3h ago
Vendor
Progressive Robot Ltd
Product
hMailServer
Attack Type
CWE-862: Missing Authorization
Vector String
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

Missing authorization on COM objects in Progressive Robot hMailServer 6.0.0 through 6.3.5 (Windows only) lets a local interactive user with no hMailServer credential read and write arbitrary files as the service account and queue mail as any sender. The service registers its COM classes with no DCOM access or launch permission and calls CoInitializeSecurity with no security descriptor, so any user logged on at the console or over Remote Desktop can activate the classes in the running service; a hMailServer.Message, its Attachments and Attachment, and a hMailServer.FetchAccount created this way carry a credential that never authenticated. Attachments.Add(path) and Attachment.SaveAs(path) performed no authorization check, and Message.Save/Copy and FetchAccount.AccountID/Save performed none either up to 6.3.3 and from 6.3.4 treated a holder with no credential as the server's own event-script host. Because the service does not impersonate the COM caller, Attachments.Add reads any file the service account can read and returns it, Attachment.SaveAs writes attacker-chosen bytes to any path it can write (on a LocalSystem installation, code execution as SYSTEM), Message.Save queues outbound mail from any address past the SMTP checks, and FetchAccount attaches a mail-fetch job to any mailbox. The objects an Application handed out behave the same once a later Authenticate on that Application fails.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.8",
  "pubDate": "2026-10-08T11:16:44.160Z",
  "pubdate": "2026-10-08T11:16:44.160Z",
  "executiveSummary": "This vulnerability involves a critical flaw in the COM/DCOM object authorization mechanisms of hMailServer versions 6.0.0 through 6.3.5.\nThe root cause is the service's failure to implement proper DCOM access/launch permissions and the invocation of CoInitializeSecurity with an empty security descriptor, which permits unauthenticated local users to interact with sensitive COM objects.\nAn unauthenticated local interactive user—such as one logged via console or Remote Desktop—can interface with the hMailServer service process without supplying legitimate credentials.\nThis vulnerability facilitates arbitrary file read/write operations, permitting an attacker to read sensitive configuration or data files and potentially achieve remote code execution (RCE) by overwriting files accessible to the service account, often SYSTEM.\nAdditionally, attackers can manipulate the mail queue, spoofing arbitrary senders and interacting with mail-fetch jobs.\nThe risk is severe, as the application fails to perform authorization checks on critical objects like hMailServer.Message and hMailServer.FetchAccount, effectively granting local attackers the privileges of the service account.",
  "technicalDetails": "The vulnerability resides in the way hMailServer registers its COM classes and initializes its security context. The service fails to define explicit DCOM access or launch permissions for its COM objects. Furthermore, the application calls CoInitializeSecurity without providing a valid security descriptor, resulting in a default security configuration that allows any locally authenticated user to activate and interface with the service's COM classes.\nBy creating instances of hMailServer.Message, its associated Attachments/Attachment objects, or hMailServer.FetchAccount, an attacker gains access to functionality intended only for authenticated administrative or service-level actors. These objects are initialized with an unauthenticated credential context, yet the application fails to adequately validate the caller's identity or permissions.\nThe exploitation flow begins when an attacker, already present on the Windows host, instantiates the vulnerable COM classes. Because the service does not perform impersonation of the COM caller, any requested file operations are executed with the security token of the hMailServer service process (typically LocalSystem).\nSpecific exploitation vectors include: 1) Arbitrary File Read: Utilizing the Attachments.Add(path) method, an attacker can extract the contents of any file readable by the service account. 2) Arbitrary File Write/RCE: Using the Attachment.SaveAs(path) method, an attacker can overwrite arbitrary files. If the service is running as SYSTEM, this allows for the replacement of system binaries or configuration files, leading to full system compromise. 3) Mail Queue Manipulation: The Message.Save method allows an attacker to inject messages into the outbound queue while spoofing any sender, bypassing SMTP-level security checks. 4) Mail-Fetch Hijacking: The FetchAccount object allows an attacker to attach or modify mail-fetch jobs for arbitrary mailboxes.\nIn versions 6.3.4 and 6.3.5, the application introduced a logic change that treats a holder with no credentials as the server's own event-script host, failing to remediate the underlying authorization bypass. The vulnerability persists until explicit security descriptors are applied to the COM objects and proper authorization checks are integrated into the method calls, ensuring that only trusted callers can invoke sensitive service functionality."
}
CVE-2026-104660: hMailServer Insecure COM Authorization (HIGH Severity, CVSS: 7.8) | Sceawere