← Vulnerability feed

Vulnerability record · CVE-2005-4085 · published 31 December 2005

CVE-2005-4085: BlueCoat WinProxy and ProxyAV Host Header Buffer Overflow

Bluecoat · Webproxy

BlueCoat WinProxy before 6.1a and the web console access functionality in ProxyAV before 2.4.2.3 contain a buffer overflow that is triggered by an overly long Host: header. A remote attacker can send a crafted HTTP request to corrupt memory and potentially execute arbitrary code on the proxy appliance.

7.5 CVSS 2.0 High EPSS 66% · top 0.7%
7.5CVSS 2.0 base score
66%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
16References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

Buffer overflow in BlueCoat (a) WinProxy before 6.1a and (b) the web console access functionality in ProxyAV before 2.4.2.3 allows remote attackers to execute arbitrary code via a long Host: header.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

high priorityThe vulnerability is remotely exploitable without authentication, has a high EPSS score, and public exploit references exist, though it is not in CISA KEV.

What it is

BlueCoat WinProxy before 6.1a and the web console access functionality in ProxyAV before 2.4.2.3 contain a buffer overflow that is triggered by an overly long Host: header. A remote attacker can send a crafted HTTP request to corrupt memory and potentially execute arbitrary code on the proxy appliance.

Impact

Successful exploitation allows remote code execution with the privileges of the affected service, giving an attacker control over the proxy. Because these are network-facing security appliances, compromise can also expose traffic passing through them.

Attack surface

The flaw is reached over the network via HTTP requests containing a long Host: header, as reflected by the AV:N/AC:L/Au:N vector. No authentication or user interaction is required.

Exploitation

CISA KEV does not list this CVE, but EPSS is high at roughly 0.66 (99th percentile) and a SecurityFocus reference is tagged Exploit, indicating public exploit material exists.

What to do

  • Upgrade WinProxy to 6.1a or later and ProxyAV to 2.4.2.3 or later per the vendor advisory.
  • If immediate patching is not possible, restrict network access to the proxy management/web console interfaces to trusted hosts only.
  • Deploy a reverse proxy or WAF rule that rejects or normalizes HTTP requests with abnormally long Host headers.
  • Monitor vendor advisories for any updated guidance, since the record is old and product support status is not stated.

Detection

  • Inspect HTTP request logs for Host headers exceeding normal length or containing unusual characters.
  • Alert on crashes, restarts, or unexpected process termination of WinProxy or ProxyAV services.
  • Monitor for post-exploitation activity such as new listening ports, unexpected outbound connections, or modified binaries on the proxy appliance.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2005-4085 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

Source: NIST National Vulnerability Database (record CVE-2005-4085), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.