CVE-2004-1211

Mercury/32 4.01a - Authenticated Buffer Overflow via IMAP Command Arguments

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 8 public exploits for CVE-2004-1211. PoCs published by Metasploit, Jacopo Cervini, MC, including Metasploit module exploits/windows/imap/mercury_rename.

AI-analyzed exploit summary This is a Metasploit module exploiting a stack buffer overflow in Mercury/32 v4.01a IMAP service via the RENAME command. It includes payload delivery and handler setup for remote code execution.

Description

Multiple buffer overflows in the IMAP service in Mercury/32 4.01a allow remote authenticated users to cause a denial of service (application crash) and possibly execute arbitrary code via long arguments to the (1) EXAMINE, (2) SUBSCRIBE, (3) STATUS, (4) APPEND, (5) CHECK, (6) CLOSE, (7) EXPUNGE, (8) FETCH, (9) RENAME, (10) DELETE, (11) LIST, (12) SEARCH, (13) CREATE, or (14) UNSUBSCRIBE commands.

Exploits (8)

exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotewindows
https://www.exploit-db.com/exploits/16484

This is a Metasploit module exploiting a stack buffer overflow in Mercury/32 v4.01a IMAP service via the RENAME command. It includes payload delivery and handler setup for remote code execution.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Mercury/32 v4.01a IMAP service
Auth required
Prerequisites: Network access to the IMAP service · Valid credentials for authentication
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by Jacopo Cervini · perlremotewindows
https://www.exploit-db.com/exploits/3561

This exploit targets a buffer overflow vulnerability in Mercury Mail Transport System (CVE-2004-1211) to achieve remote code execution. It sends a crafted payload to trigger the overflow and execute shellcode that binds a shell on port 4444.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Mercury Mail Transport System
No auth needed
Prerequisites: Network access to the target system · Mercury Mail Transport System running on the target
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC
pythonremotewindows
https://www.exploit-db.com/exploits/663

This exploit targets a buffer overflow vulnerability in Mercury Mail 4.01 (Pegasus) IMAP server via the SELECT command. It sends a crafted buffer with a return address and shellcode to achieve remote code execution.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Trivial
Reliability
Reliable
Target: Mercury Mail 4.01 (Pegasus)
Auth required
Prerequisites: Network access to the IMAP server · Valid IMAP credentials
devstral-2 · analyzed Feb 19, 2026 Full analysis →
exploitdb WORKING POC
cremotewindows
https://www.exploit-db.com/exploits/670

This is a functional remote exploit for Mercury32 IMAP server, leveraging a buffer overflow vulnerability to execute arbitrary shellcode. It supports 14 different IMAP commands to trigger the overflow and includes a bind shell payload.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Mercury32 IMAP server
Auth required
Prerequisites: Valid IMAP credentials · Network access to the target IMAP server
devstral-2 · analyzed Feb 19, 2026 Full analysis →
exploitdb WORKING POC
cremotewindows
https://www.exploit-db.com/exploits/668

This exploit targets a buffer overflow vulnerability in Mercury32 IMAP server. It sends a crafted SELECT command with a long string of 'A's followed by a return address and shellcode to achieve remote code execution, binding a shell to port 1981.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Mercury32 IMAP server
Auth required
Prerequisites: Valid IMAP credentials · Network access to the target IMAP server
devstral-2 · analyzed Feb 19, 2026 Full analysis →
exploitdb WORKING POC
cppremotewindows
https://www.exploit-db.com/exploits/4316

This is a functional exploit for CVE-2004-1211 targeting Mercury/32 SMTP Server versions 3.32 to 4.51. It leverages a pre-authentication EIP overwrite vulnerability to execute arbitrary code via a crafted buffer, including a bind shell payload.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Mercury/32 SMTP Server v3.32-v4.51
No auth needed
Prerequisites: Network access to the SMTP server · Target running vulnerable Mercury/32 SMTP Server
devstral-2 · analyzed Feb 19, 2026 Full analysis →
exploitdb WORKING POC
perldoswindows
https://www.exploit-db.com/exploits/1159

This exploit targets a buffer overflow vulnerability in Mercury/32 IMAP4 service by sending a maliciously crafted CHECK command with an oversized payload. The script connects to the target IMAP4 service, authenticates, and triggers the overflow, likely causing a denial of service or potential remote code execution.

Classification
Working Poc 95%
Attack Type
Dos
Complexity
Trivial
Reliability
Reliable
Target: Mercury/32 v4.01a
Auth required
Prerequisites: Network access to the target IMAP4 service (port 143) · Valid IMAP4 credentials
devstral-2 · analyzed Feb 19, 2026 Full analysis →
metasploit WORKING POC NORMAL
by MC · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/imap/mercury_rename.rb

This Metasploit module exploits a stack buffer overflow in Mercury/32 v4.01a IMAP service via a malformed RENAME command. It includes payload delivery for remote code execution on vulnerable Windows systems.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: Mercury/32 v4.01a IMAP service
Auth required
Prerequisites: Network access to the IMAP service · Valid credentials for authentication
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (7)

Core 7
Core References
Various Sources x_refsource_confirm
http://home.kabelfoon.nl/~jaabogae/han/m_401b.html
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/13348
Exploit, Patch, Vendor Advisory vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/11775
Mailing List mailing-list x_refsource_bugtraq
http://marc.info/?l=bugtraq&m=110193702909991&w=2
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/18318
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://www.osvdb.org/12508

Scores

EPSS 0.8054
EPSS Percentile 99.2%

Details

CWE
CWE-119
Status published
Products (1)
david_harris/mercury 4.0.1a
Published Jan 10, 2005
Tracked Since Feb 18, 2026