CuteFTP Buffer Overflow Vulnerability Allowing Arbitrary Code Execution

Vulnerability

A buffer overflow vulnerability has been identified in CuteFTP version 5.0 XP. This vulnerability allows local attackers to execute arbitrary code by injecting malicious payloads into the Site Manager label field. Attackers can create payloads longer than 520 bytes, which overwrite the return address and execute shellcode when the associated shortcut is launched.

Impact

Exploitation of this vulnerability allows for arbitrary code execution on the affected system.

Added: May 26, 2026, 7:36 PM
Updated: May 26, 2026, 7:36 PM

Vulnerability Rating

Custom Algorithm
spread
4.2
impact
7.5
exploitability
4.0
remediation
0.0
relevance
9.4
threat
6.4
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.