Heap-based buffer overflow in the legacy Blowfish decryption routine (BlowFishEncryptor::DecryptFromString) in Progressive Robot hMailServer 6.0.0 through 6.3.3 on Windows allows a local interactive user with no hMailServer credentials to write bytes of their choosing past the end of a 255-byte heap buffer in the hMailServer service process, which runs as LocalSystem by default. The user does this by passing a long hexadecimal string to the COM method Utilities.BlowfishDecrypt, which checked no authentication. The routine converted hexadecimal input of any length into a fixed 255-byte buffer before decrypting it in place. The result is a denial of service (service crash), and possibly code execution with the privileges of the service account.
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
CVE-2026-103010 is a heap-based buffer overflow vulnerability in Progressive Robot hMailServer versions 6.0.0 through 6.3.3 on Windows. The flaw exists in the legacy Blowfish decryption routine (BlowFishEncryptor::DecryptFromString) accessed via the COM method Utilities.BlowfishDecrypt. A local interactive user without hMailServer credentials can exploit this by passing an excessively long hexadecimal string, causing the decryption function to write arbitrary bytes past a 255-byte heap buffer boundary. Since hMailServer typically runs as LocalSystem, successful exploitation enables privilege escalation and complete system compromise. This is particularly dangerous because exploitation requires only local access with minimal prerequisites, making it a critical risk for organizations running legacy versions of this mail server.
While MITRE ATT&CK techniques are not formally mapped to this CVE, the exploitation pattern aligns with memory corruption attack vectors. Casky's platform would leverage Claude AI with extended reasoning to identify suspicious patterns including: unusual COM interface calls to Utilities.BlowfishDecrypt with unexpectedly large parameter values, heap memory corruption indicators in process memory analysis, and LocalSystem-context process crashes or unexpected behavior following Blowfish decryption attempts. A security practitioner using Casky would observe findings related to CWE-122 (heap-based buffer overflow) detection, which the platform maps across its 754 security skills to identify both the initial exploitation attempt and post-exploitation indicators such as arbitrary code execution or privilege escalation artifacts. The AI-enhanced analysis would correlate these signals to flag potentially compromised hMailServer instances before damage occurs.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2026-103010. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation