CVE-2012-10030 is a critical vulnerability in FreeFloat FTP Server that allows unauthenticated remote attackers to upload arbitrary files to sensitive system directories. This is due to critical design flaws including empty credential acceptance, default root C:\ drive access, and lack of restrictions on file type or destination. The vulnerability has a CVSS score of 9.8 (Critical) and allows for remote code execution with SYSTEM-level privileges, as attackers can upload executable payloads and .mof files that are automatically processed by WMI. While not in CISA's KEV catalog, a Metasploit module exists, indicating readily available exploit code, despite limited community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.0CPE matchmatch criteria | cpe:2.3:a:freefloat:freefloat_ftp_server:1.0:*:*:*:*:*:*:* | ||
All Versions ImpactedCPE match | cpe:2.3:a:freefloat:ftp_server:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.