WebAdmin allows administrators to securely manage MDaemon, RelayFax, and WorldClient from anywhere in the world. There is a remotely exploitable buffer overrun in the USER parameter.
Credit:
The information has been provided by Mark Litchfield.
By default the webadmin.exe process is started as a system service. Any code being passed to the server by an attacker as a result of this buffer overrun would therefore (based on a default install) execute with system privileges.