CVE-2009-1592

ElectraSoft 32bit FTP 09.04.24 - Stack-based Buffer Overflow via Long FTP Banner

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 2 public exploits for CVE-2009-1592. PoCs published by His0k4, Load 99%.

AI-analyzed exploit summary This exploit targets a remote buffer overflow in 32-bit FTP (09.04.24) by sending a crafted payload to port 21. It uses a JMP ESP instruction from kernel32.dll and includes Metasploit-generated shellcode to execute 'calc.exe'.

Description

Stack-based buffer overflow in ElectraSoft 32bit FTP 09.04.24 allows remote FTP servers to execute arbitrary code via a long banner. NOTE: this might overlap CVE-2003-1368.

Exploits (2)

exploitdb WORKING POC VERIFIED
by His0k4 · pythonremotewindows_x86
https://www.exploit-db.com/exploits/8614

This exploit targets a remote buffer overflow in 32-bit FTP (09.04.24) by sending a crafted payload to port 21. It uses a JMP ESP instruction from kernel32.dll and includes Metasploit-generated shellcode to execute 'calc.exe'.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Moderate
Reliability
Reliable
Target: 32-bit FTP (09.04.24)
No auth needed
Prerequisites: Network access to target FTP service on port 21 · Vulnerable version of 32-bit FTP (09.04.24)
devstral-2 · analyzed Feb 16, 2026 Full analysis →
exploitdb WORKING POC VERIFIED
by Load 99% · perldoswindows_x86
https://www.exploit-db.com/exploits/8611

This exploit triggers a buffer overflow in 32bit FTP Client 09.04.24 by sending a maliciously large FTP banner (5060 bytes of 'A's). The crash occurs due to uncontrolled data copy into a fixed-size buffer, leading to an access violation.

Classification
Working Poc 95%
Attack Type
Dos
Complexity
Trivial
Reliability
Reliable
Target: 32bit FTP Client version 09.04.24
No auth needed
Prerequisites: Network access to target · Target must initiate FTP connection to attacker-controlled server
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (7)

Core 7
Core References
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/34822
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/34993
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/50337
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2009/1263
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/8611
Exploit, Third Party Advisory exploit x_refsource_exploit-db
https://www.exploit-db.com/exploits/8614
Third Party Advisory, VDB Entry vdb-entry x_refsource_osvdb
http://osvdb.org/54219

Scores

EPSS 0.0710
EPSS Percentile 93.4%

Details

CWE
CWE-119
Status published
Products (1)
electrasoft/32bit_ftp 09.04.24
Published May 08, 2009
Tracked Since Feb 18, 2026