CVE-2008-1724

SecureTransport Server <4.6.1 - Buffer Overflow

Title source: llm

Description

Stack-based buffer overflow in the IActiveXTransfer.FileTransfer method in the SecureTransport FileTransfer ActiveX control in vcst_en.dll 1.0.0.5 in Tumbleweed SecureTransport Server before 4.6.1 Hotfix 20 allows remote attackers to execute arbitrary code via a long remoteFile parameter.

Exploits (3)

metasploit WORKING POC GREAT
rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/browser/tumbleweed_filetransfer.rb
exploitdb WORKING POC VERIFIED
by Metasploit · rubyremotewindows
https://www.exploit-db.com/exploits/16563
exploitdb WORKING POC VERIFIED
by Patrick Webster · htmlremotewindows
https://www.exploit-db.com/exploits/5398

Scores

EPSS 0.7821
EPSS Percentile 99.0%

Classification

CWE
CWE-119
Status draft

Affected Products (1)

tumbleweed/securetransport_server_app < 4.6.1

Timeline

Published Apr 11, 2008
Tracked Since Feb 18, 2026