{"id":"CVE-2026-103010","title":"Heap-based buffer overflow in the legacy Blowfish decryption routine (BlowFishEncryptor::DecryptFromString) in Progressive Robot hMailServer 6.0.0 through 6.3.3 on Windows allows a local interactive user with no hMailServer credentials t…","summary":"Heap-based buffer overflow in the legacy Blowfish decryption routine (BlowFishEncryptor::DecryptFromString) in Progressive Robot hMailServer 6.0.0 through 6.3.3 on Windows allows a local interactive user with no hMailServer credentials t…","severity":"high","cvss":7.8,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-122"],"vendor":"Progressive Robot Ltd","product":"hMailServer","affected":["hMailServer >= 6.0.0 < 6.3.4"],"published":"2026-10-08","updated":"2026-10-08","sourceUpdated":"2026-10-08T15:17:31.233","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-103010","references":[{"url":"https://gitlab.com/hmailserver/hmailserver/-/commit/135a1908ff820ed587d5f180f98c53bd010d8931","label":"cve@gitlab.com"},{"url":"https://gitlab.com/hmailserver/hmailserver/-/releases/v6.3.4","label":"cve@gitlab.com"},{"url":"https://gitlab.com/hmailserver/hmailserver/-/work_items/49","label":"cve@gitlab.com"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"total","timestamp":"2026-10-08T14:22:18.436893Z"},"ingestedAt":"2026-10-08T11:31:27.687Z","slug":"CVE-2026-103010","body":"## Overview\n\nHeap-based buffer overflow in the legacy Blowfish decryption routine (BlowFishEncryptor::DecryptFromString) in Progressive Robot hMailServer 6.0.0 through 6.3.3 on Windows allows a local interactive user with no hMailServer credentials to write bytes of their choosing past the end of a 255-byte heap buffer in the hMailServer service process, which runs as LocalSystem by default. The user does this by passing a long hexadecimal string to the COM method Utilities.BlowfishDecrypt, which checked no authentication. The routine converted hexadecimal input of any length into a fixed 255-byte buffer before decrypting it in place. The result is a denial of service (service crash), and possibly code execution with the privileges of the service account.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":43,"depthScoreParts":{"impact":42.9,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}