CVE-2004-0430

AppleFileServer <10.3.3 - Buffer Overflow

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 4 public exploits for CVE-2004-0430. PoCs published by Metasploit, Dino Dai Zovi, H D Moore, including Metasploit module exploits/osx/afp/loginext.

AI-analyzed exploit summary This exploit targets a stack buffer overflow in AppleFileServer on MacOS X (CVE-2004-0430) by sending a maliciously crafted AFP packet with an oversized path name to trigger remote code execution. It includes a Metasploit module with a hardcoded return address for Mac OS X 10.3.3.

Description

Stack-based buffer overflow in AppleFileServer for Mac OS X 10.3.3 and earlier allows remote attackers to execute arbitrary code via a LoginExt packet for a Cleartext Password User Authentication Method (UAM) request with a PathName argument that includes an AFPName type string that is longer than the associated length field.

Exploits (4)

exploitdb WORKING POC VERIFIED
by Metasploit · rubyremoteosx
https://www.exploit-db.com/exploits/16863

This exploit targets a stack buffer overflow in AppleFileServer on MacOS X (CVE-2004-0430) by sending a maliciously crafted AFP packet with an oversized path name to trigger remote code execution. It includes a Metasploit module with a hardcoded return address for Mac OS X 10.3.3.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Racy
Target: AppleFileServer on Mac OS X 10.3.3
No auth needed
Prerequisites: Network access to target on port 548 (AFP) · Target running vulnerable Mac OS X version
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by Dino Dai Zovi · perlremoteosx
https://www.exploit-db.com/exploits/391

This exploit targets a buffer overflow vulnerability in AppleFileServer (CVE-2004-0430) to achieve remote code execution. It sends a maliciously crafted FPloginEXT packet to trigger the overflow and execute a portbind shellcode, providing a root shell on the target system.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: AppleFileServer on MacOSX 10.3.3
No auth needed
Prerequisites: Network access to the target on port 548 (AFP) · Target running vulnerable version of AppleFileServer
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by H D Moore · rubyremoteosx
https://www.exploit-db.com/exploits/9931

This exploit targets a stack overflow vulnerability in the AppleFileServer service on MacOS X 10.3.3. It crafts a malicious AFP packet with an oversized path name to trigger the overflow and execute arbitrary payloads.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: AppleFileServer on MacOS X 10.3.3
No auth needed
Prerequisites: Network access to the target's AFP service (port 548)
devstral-2 · analyzed Feb 16, 2026 Full analysis →
metasploit WORKING POC NORMAL
rubypocosx
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/osx/afp/loginext.rb

This Metasploit module exploits a stack buffer overflow in the AppleFileServer service on MacOS X (CVE-2004-0430) by sending a maliciously crafted AFP packet with an oversized path name to trigger remote code execution.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Racy
Target: AppleFileServer on MacOS X 10.3.3
No auth needed
Prerequisites: Network access to target's AFP service (port 548)
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (7)

Core 7
Core References
Patch, Vendor Advisory vendor-advisory x_refsource_atstake
http://www.atstake.com/research/advisories/2004/a050304-1.txt
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/16049
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://securitytracker.com/id?1010039
US Government Resource third-party-advisory x_refsource_cert-vn
http://www.kb.cert.org/vuls/id/648406
Mailing List vendor-advisory x_refsource_apple
http://lists.apple.com/mhonarc/security-announce/msg00049.html
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/11539

Scores

EPSS 0.4130
EPSS Percentile 98.5%

Details

Status published
Products (2)
apple/mac_os_x < 10.3.3
apple/mac_os_x_server < 10.3.3
Published Jul 07, 2004
Tracked Since Feb 18, 2026