AspEmail 5.6.0.2 contains a binary permission vulnerability that allows local users to escalate privileges through the Persits Software EmailAgent service. Attackers can exploit full write permissions in the BIN directory to replace the service executable and gain elevated system access.
References
Configurations
No configuration.
History
19 Dec 2025, 21:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-12-19 21:15
Updated : 2025-12-23 14:52
NVD link : CVE-2023-53949
Mitre link : CVE-2023-53949
CVE.ORG link : CVE-2023-53949
JSON object : View
Products Affected
No product.
CWE
CWE-732
Incorrect Permission Assignment for Critical Resource
