CVE-2024-28589

MEDIUM

Axigen Mail Server for Windows < 10.5.18 - Local Privilege Escalation via Insecure DLL Loading

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2024-28589. PoCs published by Alaatk.

AI-analyzed exploit summary This repository provides a detailed writeup of CVE-2024-28589, a local privilege escalation vulnerability in Axigen Mail Server for Windows. The vulnerability arises from insecure DLL loading from a world-writable directory, allowing an attacker to execute code with SYSTEM privileges.

Description

An issue was discovered in Axigen Mail Server for Windows versions 10.5.18 and before, allows local low-privileged attackers to execute arbitrary code and escalate privileges via insecure DLL loading from a world-writable directory during service initialization.

Exploits (1)

nomisec WRITEUP 1 stars
by Alaatk · poc
https://github.com/Alaatk/CVE-2024-28589

This repository provides a detailed writeup of CVE-2024-28589, a local privilege escalation vulnerability in Axigen Mail Server for Windows. The vulnerability arises from insecure DLL loading from a world-writable directory, allowing an attacker to execute code with SYSTEM privileges.

Classification
Writeup 90%
Attack Type
Lpe
Complexity
Moderate
Reliability
Reliable
Target: Axigen Mail Server for Windows up to 10.5.18
Auth required
Prerequisites: Local access to the target system · Ability to create directories and place DLL files
MITRE ATT&CK
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Scores

CVSS v3 6.7
EPSS 0.0034
EPSS Percentile 25.8%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-732
Status published
Published Apr 03, 2024
Tracked Since Feb 18, 2026