Skip to content
KitploitKITPLOIT
ToolsBlog
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
Tools/GitHubGitHub/alaatk/cve-2024-28589
Privilege EscalationVulnerability AnalysisExploitationPenetration TestingBinary Exploitation
GitHubalaatk/cve-2024-28589

CVE-2024-28589

Local Privilege Escalation Vulnerability on Axigen for Windows

View Repository
112 years agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2024-28589

A vulnerability has been discovered in Axigen Mail Server for Windows, affecting all versions up to 10.5.18, which allows for local privilege escalation.

Description:

The Axigen Mail Server was found to be vulnerable to a local privilege escalation due to insecure DLL loading from a world-writable directory. During the service initiation of "Axigen Mail Server," which operates with SYSTEM privileges, it searches for a non-existent directory. An attacker with local access can create this directory and place a malicious DLL file in it. When the service starts, it attempts to load all DLL files in this directory, allowing the attacker's code to execute with SYSTEM privileges.

Affected versions

Axigen 10.x up to 10.5.18

fixed starting with 10.5.19

Impacted service(s)

Service Name: Axigen Mail Server

DLL loaded from world-writable directory

Alt text

Discovered by:

  • Alaa Kachouh
  • Ali Jammal of Deloitte Netherlands
Download Tool