Vulnerability record · CVE-2005-4411 · published 20 December 2005
CVE-2005-4411: Mercury Mail Transport System buffer overflow on TCP port 105
David Harris · Mercury Mail Transport System
Mercury Mail Transport System 4.01b contains a buffer overflow reachable through a long request sent to TCP port 105. A remote, unauthenticated attacker can trigger the overflow and potentially execute arbitrary code on the mail server. The record does not identify the specific component listening on port 105 or the exact overflowed buffer.
Description
Buffer overflow in Mercury Mail Transport System 4.01b allows remote attackers to execute arbitrary code via a long request to TCP port 105.
AV:N/AC:L/Au:N/C:P/I:P/A:P
Automated analysis
high priorityRemote, unauthenticated code execution with public exploit references and a very high EPSS score, though the product is old and no KEV listing exists.
What it is
Mercury Mail Transport System 4.01b contains a buffer overflow reachable through a long request sent to TCP port 105. A remote, unauthenticated attacker can trigger the overflow and potentially execute arbitrary code on the mail server. The record does not identify the specific component listening on port 105 or the exact overflowed buffer.
Impact
Successful exploitation gives the attacker arbitrary code execution in the context of the Mercury service, which typically runs with system or service-level privileges. That allows full compromise of the mail server and any data or credentials it handles.
Attack surface
The flaw is network-reachable over TCP port 105 with no authentication required, per the CVSS vector AV:N/AC:L/Au:N. No user interaction is indicated in the description or vector.
Exploitation
CISA KEV does not list this CVE, but EPSS is high at roughly 0.65 (99th percentile), and public exploit references exist, including an Exploit-DB entry and a SecurityTracker reference tagged Exploit. Working exploit code therefore appears to be publicly available.
What to do
- Upgrade Mercury Mail Transport System to a version later than 4.01b, or apply the vendor fix for this overflow.
- If port 105 is not required, block it at the perimeter and host firewall; restrict access to trusted management hosts only.
- Place the mail server behind filtering that rejects oversized or malformed requests to port 105.
- Run the Mercury service under a least-privilege account and isolate it from sensitive internal networks.
- Monitor vendor advisories for Mercury Mail Transport System and track any successor fixes.
Detection
- Alert on unusually long or malformed requests to TCP port 105 in network or IDS logs.
- Monitor the Mercury service process for crashes, restarts, or unexpected child processes.
- Watch for outbound connections or new processes spawned by the Mercury service account after port 105 traffic.
- Review host logs for memory corruption indicators or service restarts correlated with external port 105 connections.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2005-4411 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Source: NIST National Vulnerability Database (record CVE-2005-4411), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.