CVE-2019-25361
CRITICALAyukov NFTP client 1.71 - Stack-based Buffer Overflow via SYST Command
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2019-25361. PoCs published by SYANiDE.
AI-analyzed exploit summary This is a functional exploit for a buffer overflow vulnerability in Ayukov NFTP client 1.71. It leverages a crafted SYST response to overwrite EIP and execute a bind shell payload on Windows XP systems.
Description
Ayukov NFTP client 1.71 contains a buffer overflow vulnerability in the SYST command handling that allows remote attackers to execute arbitrary code. Attackers can send a specially crafted SYST command with oversized payload to trigger a buffer overflow and execute a bind shell on port 5150.
Exploits (1)
This is a functional exploit for a buffer overflow vulnerability in Ayukov NFTP client 1.71. It leverages a crafted SYST response to overwrite EIP and execute a bind shell payload on Windows XP systems.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H