Description
Heap-based buffer overflow in the legacy Blowfish decryption routine (BlowFishEncryptor::DecryptFromString) in Progressive Robot hMailServer 6.0.0 through 6.3.3 on Windows allows a local interactive user with no hMailServer credentials to write bytes of their choosing past the end of a 255-byte heap buffer in the hMailServer service process, which runs as LocalSystem by default. The user does this by passing a long hexadecimal string to the COM method Utilities.BlowfishDecrypt, which checked no authentication. The routine converted hexadecimal input of any length into a fixed 255-byte buffer before decrypting it in place. The result is a denial of service (service crash), and possibly code execution with the privileges of the service account.
Published: 2026-10-08
Score: 7.8 High
EPSS: n/a
KEV: No
Impact: Potential local privilege escalation or denial of service
Action: Immediate Patch
AI Analysis

Impact

The vulnerability lies in the legacy Blowfish decryption routine (BlowFishEncryptor::DecryptFromString) within Progressive Robot’s hMailServer. A local user who does not possess hMailServer credentials can invoke the COM method Utilities.BlowfishDecrypt with a very long hexadecimal string. Because the routine simply copies any length of hexadecimal data into a fixed 255‑byte heap buffer, an overflow occurs. The resulting memory corruption can crash the hMailServer service, causing a denial of service, and it also provides an avenue for arbitrary code execution with the privileges of the service account, which defaults to LocalSystem.

Affected Systems

The flaw affects all releases of Progressive Robot Ltd’s hMailServer from version 6.0.0 through 6.3.3 on Windows platforms. The issue was first mitigated in version 6.3.4 by correcting the buffer handling, but authentication for the COM utilities remained absent until 6.3.6, which both patches the overflow and enforces proper authentication.

Risk and Exploitability

The CVSS v3.1 score of 7.8 indicates a high severity. Attackers must be local, but they do not need any hMailServer credentials. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, so the current exploitation probability is uncertain. Because the service normally runs as LocalSystem, successful exploitation could provide system‑level code execution, making the risk significant for any environment where local users exist.

Generated by OpenCVE AI on October 8, 2026 at 12:21 UTC.

Remediation

Vendor Solution

Upgrade to hMailServer 6.3.6, which also requires authentication for the COM Utilities helpers (6.3.4 is the first release with this routine fixed).


OpenCVE Recommended Actions

  • Upgrade hMailServer to version 6.3.6 or later. This version addresses the buffer overflow and enforces authentication for COM utilities.
  • Enable or enforce authentication for the COM Utilities helpers as required in the new release. This prevents unauthenticated local users from calling the vulnerable method.
  • If the hMailServer service runs under LocalSystem, reconfigure it to run under a least‑privilege account to limit any potential code execution.

Generated by OpenCVE AI on October 8, 2026 at 12:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 08 Oct 2026 11:00:00 +0000

Type Values Removed Values Added
Description Heap-based buffer overflow in the legacy Blowfish decryption routine (BlowFishEncryptor::DecryptFromString) in Progressive Robot hMailServer 6.0.0 through 6.3.3 on Windows allows a local interactive user with no hMailServer credentials to write bytes of their choosing past the end of a 255-byte heap buffer in the hMailServer service process, which runs as LocalSystem by default. The user does this by passing a long hexadecimal string to the COM method Utilities.BlowfishDecrypt, which checked no authentication. The routine converted hexadecimal input of any length into a fixed 255-byte buffer before decrypting it in place. The result is a denial of service (service crash), and possibly code execution with the privileges of the service account.
Title Heap-based Buffer Overflow in hMailServer
Weaknesses CWE-122
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitLab

Published:

Updated: 2026-10-08T10:53:10.627Z

Reserved: 2026-09-29T21:04:45.349Z

Link: CVE-2026-103010

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-08T11:16:42.117

Modified: 2026-10-08T11:16:42.117

Link: CVE-2026-103010

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T12:30:04Z

Weaknesses
  • CWE-122

    Heap-based Buffer Overflow