Arcane Software’s Vermillion FTP Daemon (vftpd) versions up to and including 1.31 contains a memory corruption vulnerability triggered by a malformed FTP PORT command. The flaw arises from an out-of-bounds array access during input parsing, allowing an attacker to manipulate stack memory and potentially execute arbitrary code. Exploitation requires direct access to the FTP service and is constrained by a single execution attempt if the daemon is installed as a Windows service.
The vulnerability results from out-of-bounds array access during parsing of the FTP PORT command input, which is classified as improper type conversion error (CWE-704) and buffer overflow/out-of-bounds write (CWE-787). This allows an attacker to manipulate stack memory and potentially execute arbitrary code. Exploitation of the vulnerability requires direct network access to the FTP service and is limited to one exploitation attempt if the daemon runs as a Windows system service.
An attacker with network access to the FTP service can cause arbitrary code execution (RCE) on the vulnerable server, resulting in complete system compromise. Loss of confidentiality, integrity, and data availability is possible.
Apply patches available from the vendor according to the references. Due to lack of information about a newer secure version, it is recommended to consider migration to alternative, actively supported FTP server software and restrict access to the FTP service only to trusted IP addresses using a firewall.
Arcane Software Vermillion FTP Daemon (vftpd) in versions up to 1.31 inclusive, running on Windows systems.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X