CVE-2012-10055 describes a critical format string vulnerability in ComSndFTP FTP Server version 1.3.7 Beta. An unauthenticated remote attacker can exploit a specially crafted USER command to overwrite a hardcoded function pointer, specifically WSACleanup, in memory. This allows for arbitrary code execution by redirecting execution flow and bypassing DEP protections using a ROP chain. With a CVSS score of 9.3 (CRITICAL) and an EPSS score indicating high exploitability, this vulnerability poses a significant risk due to its network-based attack vector and low attack complexity. Exploit modules are available in Metasploit, and there is substantial community discussion, though it is not listed on the KEV catalog or Hot List.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| ComSndFTP | FTP Server | 1.3.7 BetaCNA affecteddefault unknown |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.