vendor:
CuteFTP
by:
Matteo Malvica
7.5
CVSS
HIGH
Buffer Overflow
CWE
Product Name: CuteFTP
Affected Version From: CuteFTP 5.0.4 XP - build 54.8.6.1
Affected Version To: CuteFTP 5.0.4 XP - build 54.8.6.1
Patch Exists: NO
Related CWE:
CPE: a:globalscape:cuteftp:5.0.4
Platforms Tested: Windows XP Profesional SP3 English x86
2018
CuteFTP 5.0 – Buffer Overflow
This exploit allows an attacker to execute arbitrary code on a target system by exploiting a buffer overflow vulnerability in CuteFTP 5.0. By creating a specially crafted shortcut, the attacker can trigger the overflow and gain control of the system. The exploit generates an 'exploit.txt' file and uses a python script to automate the process.
Mitigation:
Apply the latest patch from the vendor to fix the buffer overflow vulnerability.