vendor:
Konica Minolta FTP Utility
by:
Alvaro J. Gene (Socket_0x03)
7.5
CVSS
HIGH
Denial of Service
119
CWE
Product Name: Konica Minolta FTP Utility
Affected Version From: 1
Affected Version To: 1
Patch Exists: NO
Related CWE:
CPE: a:konica_minolta:ftp_utility:1.0
Platforms Tested: Windows 7 SP1
2020
Konica Minolta FTP Utility 1.0 – ‘LIST’ Denial of Service (PoC)
There is a buffer overflow vulnerability in the LIST command of the FTP server 'Konica Minolta FTP Utility' that allows an attacker to overwrite registers such as EAX, ESI, EDI. By using the vulnerable command, an individual can build a remote buffer overflow exploit that can root a system without any user interaction.
Mitigation:
Update to a patched version of the software.