Windows Tftp Utility is a legacy file-transfer component with a narrow, historically embedded presence in Windows systems, where disclosed vulnerabilities center on input validation and path-traversal weaknesses in the tftputil implementation. These flaws reflect the minimal parsing and access-control rigor typical of older utility components; current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Windows Tftp Utility over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2009-0288MEDIUM Directory traversal vulnerability in k23productions TFTPUtil GUI 1.2.0 and 1.3.0 allows remote attackers to read arbitrary files outside the TFTP root directory via directory trave | Jan 27, 2009 | 5.0 | 18 | NO | NO |
CVE-2009-0289MEDIUM k23productions TFTPUtil GUI 1.2.0 and 1.3.0 allows remote attackers to cause a denial of service (service crash) via a long filename in a crafted request. | Jan 27, 2009 | 5.0 | 17 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Windows Tftp Utility.
Media articles that mention a CVE ID that affects a product developed by Windows Tftp Utility — matched by CVE ID, not by vendor name.