Vulnerability record · CVE-2003-0772 · published 22 September 2003
CVE-2003-0772: WS_FTP Server buffer overflows in APPE and STAT commands
Ipswitch · Ws Ftp Server
WS_FTP 3 and 4 contain multiple buffer overflows reachable through long APPE (append) or STAT (status) command arguments. A remote authenticated user can crash the service and possibly execute arbitrary code on the FTP server. The flaw matters because it lets a low-privileged FTP account reach code execution on the host.
Description
Multiple buffer overflows in WS_FTP 3 and 4 allow remote authenticated users to cause a denial of service and possibly execute arbitrary code via long (1) APPE (append) or (2) STAT (status) arguments.
AV:N/AC:L/Au:N/C:P/I:P/A:P
Automated analysis
high priorityRemote authenticated code execution with public exploit references and a very high EPSS score, though exploitation requires valid credentials.
What it is
WS_FTP 3 and 4 contain multiple buffer overflows reachable through long APPE (append) or STAT (status) command arguments. A remote authenticated user can crash the service and possibly execute arbitrary code on the FTP server. The flaw matters because it lets a low-privileged FTP account reach code execution on the host.
Impact
An attacker with valid FTP credentials gains denial of service against the server and potentially arbitrary code execution under the FTP service account. That can lead to full host compromise depending on service privileges.
Attack surface
Reached over the network through the FTP command channel by sending oversized APPE or STAT arguments. Authentication is required per the description, and no user interaction beyond issuing FTP commands is needed.
Exploitation
Not listed in CISA KEV and no ransomware use documented, but EPSS is very high (0.849, 99.7th percentile) and a SecurityFocus reference is tagged Exploit, indicating public exploit material exists.
What to do
- Apply the vendor patch or upgrade to a fixed WS_FTP Server release; if none is available, retire or isolate the affected version.
- Restrict FTP access to trusted networks and disable anonymous or shared accounts.
- Enforce strict input length limits on FTP command arguments at a proxy or gateway where possible.
- Run the FTP service with least privilege and isolate it from sensitive internal systems.
- Monitor vendor and CERT/CC advisories for updated guidance on this legacy product.
Detection
- Alert on FTP APPE or STAT commands with abnormally long arguments in server or IDS logs.
- Monitor for repeated FTP service crashes or restarts correlated with authenticated sessions.
- Watch for unexpected child processes or outbound connections spawned by the FTP service account.
- Baseline normal FTP command lengths per account and flag outliers.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://marc.info/?l=bugtraq&m=106288825902868&w=2 | |
| http://secunia.com/advisories/9671 | |
| http://www.kb.cert.org/vuls/id/219140 | US Government Resource |
| http://www.kb.cert.org/vuls/id/792284 | US Government Resource |
| http://www.securityfocus.com/bid/8542 | ExploitVendor Advisory |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/13119 | |
| http://marc.info/?l=bugtraq&m=106288825902868&w=2 | |
| http://secunia.com/advisories/9671 | |
| http://www.kb.cert.org/vuls/id/219140 | US Government Resource |
| http://www.kb.cert.org/vuls/id/792284 | US Government Resource |
| http://www.securityfocus.com/bid/8542 | ExploitVendor Advisory |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/13119 |
Track CVE-2003-0772 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2003-0772), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.