Actively Exploited in the Wild

This vulnerability is being actively exploited in the wild.

Vermillion FTP Daemon Memory Corruption Vulnerability via Malformed PORT Command

Vulnerability

A memory corruption vulnerability has been identified in Arcane Software's Vermillion FTP Daemon (vftpd) versions through 1.31. The issue is triggered by a malformed FTP PORT command, leading to an out-of-bounds array access during input parsing. This flaw allows an attacker to manipulate stack memory, with the potential to execute arbitrary code. Exploitation requires direct access to the FTP service and is limited to a single attempt if the daemon is installed as a Windows service.

Impact

Exploitation of this vulnerability can result in a buffer overflow, allowing for arbitrary code execution within the context of the FTP service.

Reproduction

The vulnerability can be reproduced by sending a crafted FTP PORT command that exploits the out-of-bounds array access. This can be done manually or using the available Metasploit module. The Metasploit module automates the exploitation process by first sending the payload to the USER and PASS commands, and then delivering the exploit via the PORT command.

Added: Aug 21, 2025, 9:23 PM
Updated: Aug 21, 2025, 9:23 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
7.5
exploitability
6.9
remediation
0.0
relevance
0.4
threat
9.1
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.