ComSndFTP v1.3.7 Beta USER Format String RCE
Vulnerability Description
ComSndFTP FTP Server version 1.3.7 Beta contains a format string vulnerability in its handling of the USER command. By sending a specially crafted username containing format specifiers, a remote attacker can overwrite a hardcoded function pointer in memory (specifically WSACleanup from Ws2_32.dll). This allows the attacker to redirect execution flow and bypass DEP protections using a ROP chain, ultimately leading to arbitrary code execution. The vulnerability is exploitable without authentication and affects default configurations.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2012-10055
Credits & Attribution
The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:
- ChaoYi Huang
References
- https://raw.githubusercontent.com/rapid7/metasploit-framework/master/modules/exploits/windows/ftp/comsnd_ftpd_fmtstr.rb
- https://www.exploit-db.com/exploits/19024
- https://www.exploit-db.com/exploits/19177
- https://web.archive.org/web/20120317214524/http://ftp.comsnd.com/
- https://www.vulncheck.com/advisories/comsndftp-user-format-string-rce
Affected Vendor
ComSndFTP
View all reports →Affected Software
Timeline
CVSS Vectors
Weaknesses (CWE)
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.