An issue in HSC Cybersecurity HC Mailinspector 5.2.17-3 through 5.2.18 allows a remote attacker to obtain sensitive information via a crafted payload to the id parameter in the mliSystemUsers.php component.
The product implements an IOCTL with functionality that should be restricted, but it does not properly enforce access control for the IOCTL.