vendor:
Core FTP Client LE
by:
Berk Cem Göksel
9.8
CVSS
CRITICAL
Buffer Overflow
119
CWE
Product Name: Core FTP Client LE
Affected Version From: Core FTP Client LE v2.2 Build 1921
Affected Version To: Core FTP Client LE v2.2 Build 1921
Patch Exists: YES
Related CWE: CVE-2018-12113
CPE: a:coreftp:core_ftp_client_le:2.2
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows 10
2018
Core FTP LE 2.2 – Buffer Overflow (PoC)
The vulnerability was discovered during a vulnerability research lecture. This is meant to be a PoC. The exploit is a python script which binds a FTP server to a port and sends a malicious payload to the server.
Mitigation:
The vendor has released a patch to address this vulnerability.