CVE-2006-5177 EXPLOIT
9.3
HIGH · CVSS 2.0 · EPSS 7.1% (pctl 94)
Patch early
A public exploit exists.
Description
The NTLM authentication in MailEnable Professional 2.0 and Enterprise 2.0 allows remote attackers to (1) execute arbitrary code via unspecified vectors involving crafted base64 encoded NTLM Type 3 messages, or (2) cause a denial of service via crafted base64 encoded NTLM Type 1 messages, which trigger a buffer over-read.
Scoring
| CVSS | 9.3 (HIGH, v2.0) |
|---|---|
| Vector | AV:N/AC:M/Au:N/C:C/I:C/A:C |
| EPSS | 7.13% — more likely to be exploited than 94% of all CVEs |
| Weakness | CWE-119 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2006-10-10 |
| Last modified | 2026-06-16 |
Affected (2)
| Vendor | Product |
|---|---|
| mailenable | mailenable enterprise |
| mailenable | mailenable professional |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | MailEnable 2.x - SMTP NTLM Multiple Authentication Vulnerabilities | 2006-11-29 |
References
- http://labs.musecurity.com/advisories/MU-200609-01.txt
- http://secunia.com/advisories/22179
- http://www.mailenable.com/hotfix/
- http://www.securityfocus.com/bid/20290
- http://www.vupen.com/english/advisories/2006/3862
- https://exchange.xforce.ibmcloud.com/vulnerabilities/29286
- https://exchange.xforce.ibmcloud.com/vulnerabilities/29287
- http://labs.musecurity.com/advisories/MU-200609-01.txt
- http://secunia.com/advisories/22179
- http://www.mailenable.com/hotfix/
- http://www.securityfocus.com/bid/20290
- http://www.vupen.com/english/advisories/2006/3862
- https://exchange.xforce.ibmcloud.com/vulnerabilities/29286
- https://exchange.xforce.ibmcloud.com/vulnerabilities/29287
→ the Explorer · watch your stack · NVD