Executive brief
CuteFTP is a file transfer application used to move files between computers and servers. A security flaw in older versions allows a local user to take full control of the system by entering a specially crafted, overly long name into the Site Manager tool. If a shortcut is then created and launched from this malicious entry, it can trigger the execution of unauthorized commands or malware.
Technical details
A stack-based buffer overflow exists in CuteFTP 5.0.4 XP within the 'Site Manager' component. The vulnerability is triggered when a user inputs a string exceeding 520 bytes into the 'label' field of a new site entry. By crafting a malicious payload that overwrites the return address on the stack, an attacker can achieve arbitrary code execution. Exploitation requires the attacker to have local access to the application to create the malicious entry and subsequently generate and launch a desktop shortcut for that entry, which triggers the shellcode execution. This is a classic CWE-120 'Buffer Copy without Checking Size of Input' vulnerability.
Affected products
- GlobalSCAPE CuteFTP XP 5.0.4 and earlier
Timeline
- 2018-08-26: disclosed: Original exploit code published by Matteo Malvica
- 2026-05-25: advisory: CVE-2018-25366 published/updated in NVD via VulnCheck enrichment