Executive brief
NICO-FTP is a file transfer application used to move data between computers. A critical security flaw allows a remote attacker to take complete control of a computer running this software by sending specially crafted, oversized data during an FTP session. This could lead to the theft of sensitive files, installation of malware, or a total system compromise.
Technical details
A stack-based buffer overflow exists in NICO-FTP version 3.0.1.19 and earlier. The vulnerability is triggered when the application processes oversized data in response handlers for FTP commands. By sending a specifically crafted payload, a remote unauthenticated attacker can overwrite Structured Exception Handler (SEH) pointers on the stack. This allows the attacker to redirect the application's execution flow to injected shellcode, leading to arbitrary code execution with the privileges of the application. A proof-of-concept exploit utilizing an egghunter technique has been publicly disclosed.
Affected products
- nico-ftp project NICO-FTP 3.0.1.19 and earlier
Timeline
- 2018-09-04: disclosed: Initial discovery and exploit development by researcher Abdullah Alıç
- 2018-09-20: other: Exploit published to Exploit-DB
- 2026-04-04: advisory: CVE formally published/assigned via VulnCheck