Heap-based buffer overflow in the legacy Blowfish decryption routine (BlowFishEncryptor::DecryptFromString) in Progressive Robot hMailServer 6.0.0 through 6.3.3 on Windows allows a local interactive user with no hMailServer credentials to write bytes of their choosing past the end of a 255-byte heap buffer in the hMailServer service process, which runs as LocalSystem by default. The user does this by passing a long hexadecimal string to the COM method Utilities.BlowfishDecrypt, which checked no authentication. The routine converted hexadecimal input of any length into a fixed 255-byte buffer before decrypting it in place. The result is a denial of service (service crash), and possibly code execution with the privileges of the service account.
Advisories

No advisories yet.

Fixes

Solution

Upgrade to hMailServer 6.3.6, which also requires authentication for the COM Utilities helpers (6.3.4 is the first release with this routine fixed).


Workaround

No workaround given by the vendor.

History

Thu, 08 Oct 2026 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 08 Oct 2026 11:00:00 +0000

Type Values Removed Values Added
Description Heap-based buffer overflow in the legacy Blowfish decryption routine (BlowFishEncryptor::DecryptFromString) in Progressive Robot hMailServer 6.0.0 through 6.3.3 on Windows allows a local interactive user with no hMailServer credentials to write bytes of their choosing past the end of a 255-byte heap buffer in the hMailServer service process, which runs as LocalSystem by default. The user does this by passing a long hexadecimal string to the COM method Utilities.BlowfishDecrypt, which checked no authentication. The routine converted hexadecimal input of any length into a fixed 255-byte buffer before decrypting it in place. The result is a denial of service (service crash), and possibly code execution with the privileges of the service account.
Title Heap-based Buffer Overflow in hMailServer
Weaknesses CWE-122
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: GitLab

Published:

Updated: 2026-10-08T14:22:28.966Z

Reserved: 2026-09-29T21:04:45.349Z

Link: CVE-2026-103010

cve-icon Vulnrichment

Updated: 2026-10-08T14:22:24.964Z

cve-icon NVD

Status : Received

Published: 2026-10-08T11:16:42.117

Modified: 2026-10-08T15:17:31.233

Link: CVE-2026-103010

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-08T12:30:04Z

Weaknesses