CVE-2012-10055 - CVE House
Back to Database
Status published Critical CVE-2012-10055

ComSndFTP v1.3.7 Beta USER Format String RCE

Vulnerability Description

ComSndFTP FTP Server version 1.3.7 Beta contains a format string vulnerability in its handling of the USER command. By sending a specially crafted username containing format specifiers, a remote attacker can overwrite a hardcoded function pointer in memory (specifically WSACleanup from Ws2_32.dll). This allows the attacker to redirect execution flow and bypass DEP protections using a ROP chain, ultimately leading to arbitrary code execution. The vulnerability is exploitable without authentication and affects default configurations.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2012-10055

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • ChaoYi Huang

Affected Vendor

Affected Software

FTP Server
Vulnerable Versions:
1.3.7 Beta

Timeline

Official Publish: August 13th, 2025
Last Modified: July 15th, 2026
Added to House: July 19th, 2026

CVSS Vectors

Weaknesses (CWE)

MITRE ATT&CK TTPs

No associated TTPs found for this vulnerability.