Vulnerability record · CVE-2005-4085 · published 31 December 2005
CVE-2005-4085: BlueCoat WinProxy and ProxyAV Host Header Buffer Overflow
Bluecoat · Webproxy
BlueCoat WinProxy before 6.1a and the web console access functionality in ProxyAV before 2.4.2.3 contain a buffer overflow that is triggered by an overly long Host: header. A remote attacker can send a crafted HTTP request to corrupt memory and potentially execute arbitrary code on the proxy appliance.
Description
Buffer overflow in BlueCoat (a) WinProxy before 6.1a and (b) the web console access functionality in ProxyAV before 2.4.2.3 allows remote attackers to execute arbitrary code via a long Host: header.
AV:N/AC:L/Au:N/C:P/I:P/A:P
Automated analysis
high priorityThe vulnerability is remotely exploitable without authentication, has a high EPSS score, and public exploit references exist, though it is not in CISA KEV.
What it is
BlueCoat WinProxy before 6.1a and the web console access functionality in ProxyAV before 2.4.2.3 contain a buffer overflow that is triggered by an overly long Host: header. A remote attacker can send a crafted HTTP request to corrupt memory and potentially execute arbitrary code on the proxy appliance.
Impact
Successful exploitation allows remote code execution with the privileges of the affected service, giving an attacker control over the proxy. Because these are network-facing security appliances, compromise can also expose traffic passing through them.
Attack surface
The flaw is reached over the network via HTTP requests containing a long Host: header, as reflected by the AV:N/AC:L/Au:N vector. No authentication or user interaction is required.
Exploitation
CISA KEV does not list this CVE, but EPSS is high at roughly 0.66 (99th percentile) and a SecurityFocus reference is tagged Exploit, indicating public exploit material exists.
What to do
- Upgrade WinProxy to 6.1a or later and ProxyAV to 2.4.2.3 or later per the vendor advisory.
- If immediate patching is not possible, restrict network access to the proxy management/web console interfaces to trusted hosts only.
- Deploy a reverse proxy or WAF rule that rejects or normalizes HTTP requests with abnormally long Host headers.
- Monitor vendor advisories for any updated guidance, since the record is old and product support status is not stated.
Detection
- Inspect HTTP request logs for Host headers exceeding normal length or containing unusual characters.
- Alert on crashes, restarts, or unexpected process termination of WinProxy or ProxyAV services.
- Monitor for post-exploitation activity such as new listening ports, unexpected outbound connections, or modified binaries on the proxy appliance.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2005-4085 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2005-4085), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.