Impact
A heap-based buffer overflow exists in the Windows FTP Service that permits an unauthorized attacker to execute arbitrary code over a network. The flaw exploits a buffer overflow weakness (CWE-122) by corrupting memory within the service's heap, giving the attacker control of the code path of the FTP Service process and resulting in remote code execution.
Affected Systems
Microsoft Windows 10 versions 1607, 1809, 21H2, 22H2; Windows 11 versions 23H2, 24H2, 25H2, 26H1; and Windows Server releases 2019, 2022 and 2025—including their Server Core variants—are affected when the Windows FTP Service is installed and running.
Risk and Exploitability
The CVSS score of 9.8 indicates critical severity, while the EPSS score of less than 1% suggests a low likelihood of exploitation in the wild. The vulnerability is not currently listed in the CISA KEV catalog. An attacker with network connectivity to port 21 can trigger the heap overflow by sending a specially crafted request, and if successful gains code execution with the privileges of the FTP Service process.
OpenCVE Enrichment