Konica Minolta FTP Utility Buffer Overflow Vulnerability in LIST Command Allowing Denial-of-Service

Vulnerability

A buffer overflow vulnerability has been identified in Konica Minolta FTP Utility version 1.0. The issue arises in the LIST command, where attackers can send an oversized buffer of 1500 'A' characters. This exploitation overwrites system registers, crashes the FTP server, and potentially allows for unauthorized code execution.

Impact

Exploitation of this vulnerability leads to a denial-of-service condition on the FTP server, causing it to crash. Additionally, the buffer overflow allows for overwriting of system registers, which could be leveraged to execute unauthorized code. According to the vulnerability advisory, this could be developed into a remote buffer overflow exploit that gains root access on the system without user interaction.

Reproduction

The vulnerability can be reproduced by using an FTP client to connect to the vulnerable FTP server running Konica Minolta FTP Utility 1.0 on Windows. After logging in, the LIST command can be issued with a buffer of 1500 'A' characters. This will overwrite registers such as EAX, ESI, and EDI, crash the FTP server, and demonstrate the potential for unauthorized code execution.

Added: Feb 3, 2026, 10:52 PM
Updated: Feb 3, 2026, 10:52 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
8.7
remediation
0.0
relevance
2.5
threat
6.4
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.