Vulnerability record · CVE-2005-3155 · published 5 October 2005
CVE-2005-3155: MailEnable W3C logging buffer overflow allows remote code execution
Mailenable · Mailenable Enterprise
MailEnable Enterprise 1.1 and Professional 1.6 contain a buffer overflow in the W3C logging component. A remote, unauthenticated attacker can trigger the overflow and potentially execute arbitrary code on the mail server. The flaw matters because mail servers are internet-facing and this path requires no credentials.
Description
Buffer overflow in the W3C logging for MailEnable Enterprise 1.1 and Professional 1.6 allows remote attackers to execute arbitrary code.
AV:N/AC:L/Au:N/C:P/I:P/A:P
Automated analysis
high priorityRemote unauthenticated code execution in an internet-facing mail server with a high EPSS score, though no confirmed in-the-wild exploitation is documented.
What it is
MailEnable Enterprise 1.1 and Professional 1.6 contain a buffer overflow in the W3C logging component. A remote, unauthenticated attacker can trigger the overflow and potentially execute arbitrary code on the mail server. The flaw matters because mail servers are internet-facing and this path requires no credentials.
Impact
An attacker can corrupt memory in the logging process and, if the overflow is reliably controlled, execute arbitrary code with the privileges of the MailEnable service. At minimum, a crash of the logging component is achievable.
Attack surface
The vulnerability is network-reachable (CVSS vector AV:N/AC:L/Au:N) and requires no authentication or user interaction. It is triggered through the W3C logging functionality, meaning crafted requests handled by the affected MailEnable service reach the vulnerable code path.
Exploitation
Not listed in CISA KEV and no ransomware associations are documented. EPSS is high (0.63694, 99.18th percentile), and references include vendor patch and advisory links, but no public exploit tag is present in the record.
What to do
- Apply the vendor hotfix from mailenable.com/hotfix and the patch referenced in Secunia advisory 17010.
- If patching cannot be done immediately, restrict network access to the MailEnable SMTP/HTTP services to trusted sources only.
- Disable or reduce W3C logging if it is not operationally required, to remove the vulnerable code path.
- Run the MailEnable service under a least-privileged account to limit the impact of code execution.
- Monitor vendor advisories for updated builds covering Enterprise 1.1 and Professional 1.6.
Detection
- Review MailEnable service crash logs and Windows event logs for repeated faults in the logging component.
- Inspect W3C log files and inbound requests for unusually long or malformed fields that could trigger the overflow.
- Alert on unexpected child processes or command execution spawned by the MailEnable service account.
- Correlate network traffic to MailEnable ports with crash or restart events on the host.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2005-3155 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2005-3155), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.