vendor:
Core FTP LE
by:
Ismael Nava
7.5
CVSS
HIGH
Denial of Service
119
CWE
Product Name: Core FTP LE
Affected Version From: 2.2
Affected Version To: 2.2 build 1947
Patch Exists: YES
Related CWE: n/a
CPE: a:coreftp:core_ftp_le
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows 10 Home x64
2020
Core FTP LE 2.2 – Denial of Service (PoC)
When a maliciously crafted file is opened in Core FTP LE 2.2, the program crashes and is unable to be reopened until it is uninstalled and reinstalled. This is due to a buffer overflow vulnerability in the program.
Mitigation:
Ensure that all software is up to date and patched to the latest version.