Impact
The vulnerability lies in the legacy Blowfish decryption routine (BlowFishEncryptor::DecryptFromString) within Progressive Robot’s hMailServer. A local user who does not possess hMailServer credentials can invoke the COM method Utilities.BlowfishDecrypt with a very long hexadecimal string. Because the routine simply copies any length of hexadecimal data into a fixed 255‑byte heap buffer, an overflow occurs. The resulting memory corruption can crash the hMailServer service, causing a denial of service, and it also provides an avenue for arbitrary code execution with the privileges of the service account, which defaults to LocalSystem.
Affected Systems
The flaw affects all releases of Progressive Robot Ltd’s hMailServer from version 6.0.0 through 6.3.3 on Windows platforms. The issue was first mitigated in version 6.3.4 by correcting the buffer handling, but authentication for the COM utilities remained absent until 6.3.6, which both patches the overflow and enforces proper authentication.
Risk and Exploitability
The CVSS v3.1 score of 7.8 indicates a high severity. Attackers must be local, but they do not need any hMailServer credentials. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, so the current exploitation probability is uncertain. Because the service normally runs as LocalSystem, successful exploitation could provide system‑level code execution, making the risk significant for any environment where local users exist.
OpenCVE Enrichment