Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

msrc логотип

CVE-2026-49172

Опубликовано: 14 июл. 2026
Источник: msrc
CVSS3: 9.8
EPSS Низкий

Описание

Windows FTP Service Remote Code Execution Vulnerability

Heap-based buffer overflow in Windows FTP Service allows an unauthorized attacker to execute code over a network.

FAQ

How could an attacker exploit this vulnerability?

An attacker could exploit this vulnerability by sending specially crafted FTP commands that exceed the expected length to a vulnerable FTP service. When the service processes and logs these oversized commands, it may write beyond the bounds of allocated memory, causing memory corruption that could lead to a service crash or allow code execution.

Обновления

ПродуктСтатьяОбновление
Windows 10 Version 1607 for 32-bit Systems
Windows 10 Version 1809 for 32-bit Systems
Windows 10 Version 1809 for x64-based Systems
Windows Server 2019
Windows Server 2019 (Server Core installation)
Windows Server 2022
Windows Server 2022 (Server Core installation)
Windows 10 Version 21H2 for 32-bit Systems
Windows 10 Version 21H2 for ARM64-based Systems
Windows 10 Version 21H2 for x64-based Systems

Показывать по

Возможность эксплуатации

Publicly Disclosed

No

Exploited

No

Latest Software Release

Exploitation Less Likely

EPSS

Процентиль: 48%
0.00673
Низкий

9.8 Critical

CVSS3

Связанные уязвимости

CVSS3: 9.8
nvd
16 дней назад

Heap-based buffer overflow in Windows FTP Service allows an unauthorized attacker to execute code over a network.

CVSS3: 9.8
github
16 дней назад

Heap-based buffer overflow in Windows FTP Service allows an unauthorized attacker to execute code over a network.

EPSS

Процентиль: 48%
0.00673
Низкий

9.8 Critical

CVSS3