Vulnerability record · CVE-2005-1256 · published 25 May 2005
CVE-2005-1256: IMail IMAP daemon stack buffer overflow via STATUS command
Ipswitch · Imail
The IMAP daemon (IMAPD32.EXE) in Ipswitch IMail 8.13 and other versions before IMail Server 8.2 Hotfix 2 contains a stack-based buffer overflow triggered by a STATUS command with an overly long mailbox name. A remote authenticated user can corrupt the stack and potentially execute arbitrary code on the mail server.
Description
Stack-based buffer overflow in the IMAP daemon (IMAPD32.EXE) in IMail 8.13 in Ipswitch Collaboration Suite (ICS), and other versions before IMail Server 8.2 Hotfix 2, allows remote authenticated users to execute arbitrary code via a STATUS command with a long mailbox name.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
high priorityThe flaw is a remotely reachable stack buffer overflow with a CVSS 2.0 score of 10 and a very high EPSS percentile, though exploitation requires valid IMAP credentials and no public exploit is confirmed.
What it is
The IMAP daemon (IMAPD32.EXE) in Ipswitch IMail 8.13 and other versions before IMail Server 8.2 Hotfix 2 contains a stack-based buffer overflow triggered by a STATUS command with an overly long mailbox name. A remote authenticated user can corrupt the stack and potentially execute arbitrary code on the mail server.
Impact
Successful exploitation allows an attacker to execute arbitrary code with the privileges of the IMAP daemon, giving full control of the mail server process and potentially the host. This can lead to data compromise, mail interception, or use of the server as a pivot point.
Attack surface
Reachable over the network through the IMAP service; the CVSS vector indicates no authentication is required, though the description states the attacker must be a remote authenticated user, so valid IMAP credentials are needed. No user interaction is required.
Exploitation
Not listed in CISA KEV and no ransomware associations are documented. EPSS shows a high 30-day probability (0.589, 99th percentile), and references include a vendor advisory and patch, but no public exploit code is confirmed in the record.
What to do
- Apply IMail Server 8.2 Hotfix 2 or later, which the vendor patch reference addresses.
- If patching is not immediately possible, restrict IMAP access to trusted networks or disable the IMAP service until the fix is applied.
- Enforce strong, unique credentials and monitor for unusual authenticated IMAP sessions to limit abuse of the authenticated attack path.
- Segment the mail server from other critical systems to reduce the blast radius if code execution occurs.
Detection
- Monitor IMAP logs for STATUS commands containing abnormally long mailbox names or malformed arguments.
- Alert on IMAPD32.EXE crashes or unexpected process terminations on IMail servers.
- Watch for post-exploitation behavior such as new processes spawned by the IMAP daemon or outbound connections from the mail server.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2005-1256 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2005-1256), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.