Sceawere
Vulnerability Detail
CVE-2026-103010UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
hMailServer Heap-Based Buffer Overflow
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.8
- Creation Date
- 3h ago
- Vendor
- Progressive Robot Ltd
- Product
- hMailServer
- Attack Type
- CWE-122: Heap-based Buffer Overflow
- Vector String
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
Heap-based buffer overflow in the legacy Blowfish decryption routine (BlowFishEncryptor::DecryptFromString) in Progressive Robot hMailServer 6.0.0 through 6.3.3 on Windows allows a local interactive user with no hMailServer credentials to write bytes of their choosing past the end of a 255-byte heap buffer in the hMailServer service process, which runs as LocalSystem by default. The user does this by passing a long hexadecimal string to the COM method Utilities.BlowfishDecrypt, which checked no authentication. The routine converted hexadecimal input of any length into a fixed 255-byte buffer before decrypting it in place. The result is a denial of service (service crash), and possibly code execution with the privileges of the service account.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.8",
"pubDate": "2026-10-08T11:16:42.117Z",
"pubdate": "2026-10-08T11:16:42.117Z",
"executiveSummary": "A critical heap-based buffer overflow vulnerability exists within the Blowfish decryption routine of Progressive Robot hMailServer versions 6.0.0 through 6.3.3.\nThe vulnerability originates in the Utilities.BlowfishDecrypt COM method, which fails to perform adequate bounds checking on user-supplied hexadecimal input before processing it within a fixed-size 255-byte heap buffer.\nThis flaw allows a local interactive user, even without existing hMailServer credentials, to trigger a memory corruption event by providing an oversized input string.\nThe hMailServer service process executes with LocalSystem privileges by default, meaning successful exploitation can lead to a complete denial of service through process termination or potentially arbitrary code execution under the context of the high-privileged SYSTEM account.\nBecause the COM method lacks authentication requirements, an attacker with local access can interact directly with this component, posing a severe risk to system integrity and service availability.",
"technicalDetails": "The vulnerability resides in the BlowFishEncryptor::DecryptFromString function, which handles decryption operations for the Utilities.BlowfishDecrypt COM interface. The root cause is a lack of input validation regarding the length of the hexadecimal string passed to the method.\nWhen the COM method is invoked, the application logic proceeds to convert the arbitrary-length hexadecimal input into raw bytes. During this transformation, the routine attempts to store the resulting data into a heap-allocated buffer with a strict, fixed size of 255 bytes. Because the application does not verify if the converted byte length exceeds the capacity of this destination buffer, it performs a heap-based buffer overflow.\nThe attack flow begins with a local interactive user leveraging the COM object interface to call the Utilities.BlowfishDecrypt method. The attacker supplies a crafted hexadecimal string exceeding 255 bytes. The routine proceeds to process the conversion, writing data past the boundaries of the allocated 255-byte heap chunk. This action overwrites adjacent heap metadata or other sensitive memory objects within the service process address space.\nSince the hMailServer service operates with LocalSystem privileges, any memory corruption induced by the attacker has significant implications. If the overflow overwrites critical function pointers or execution flow control structures, the attacker may gain control over the instruction pointer, leading to arbitrary code execution. At a minimum, the corruption of heap structures causes an unhandled memory exception, resulting in an immediate crash of the hMailServer service process (Denial of Service).\nThis vulnerability is particularly dangerous because the affected COM method is exposed without requiring any form of prior authentication, enabling any local user to interact with the vulnerable code path. The combination of high-privilege process execution and missing input validation makes this a significant local escalation and stability vector."
}