Vulnerability record · CVE-2004-0330 · published 23 November 2004
CVE-2004-0330: Serv-U FTP MDTM time zone buffer overflow allows remote code execution
Solarwinds · Serv U File Server
Serv-U FTP versions before 5.0.0.4 contain a buffer overflow in the handling of the time zone argument to the MDTM command. A remote authenticated FTP user can send an overly long time zone value and overwrite memory, which matters because it can lead to arbitrary code execution on the FTP server.
Description
Buffer overflow in Serv-U ftp before 5.0.0.4 allows remote authenticated users to execute arbitrary code via a long time zone argument to the MDTM command.
AV:N/AC:L/Au:N/C:C/I:C/A:C
Automated analysis
high priorityThe flaw allows remote code execution with complete impact and has very high EPSS and public exploit references, though it requires valid FTP credentials and affects an old product version.
What it is
Serv-U FTP versions before 5.0.0.4 contain a buffer overflow in the handling of the time zone argument to the MDTM command. A remote authenticated FTP user can send an overly long time zone value and overwrite memory, which matters because it can lead to arbitrary code execution on the FTP server.
Impact
An attacker with valid FTP credentials gains the ability to execute arbitrary code in the context of the Serv-U service, potentially taking full control of the host. The CVSS 2.0 vector rates confidentiality, integrity and availability impact as complete.
Attack surface
The flaw is reached over the network through the FTP MDTM command, so no local access is required. Authentication is needed per the description, but no user interaction beyond issuing the crafted command is described.
Exploitation
The record is not listed in CISA KEV and no ransomware usage is documented, but EPSS is very high at 0.8547 (99.71st percentile) and a reference is tagged Exploit, indicating public exploit material exists.
What to do
- Upgrade Serv-U FTP to version 5.0.0.4 or later, which is the fixed release named in the advisory.
- If immediate upgrade is not possible, restrict FTP access to trusted networks and accounts, and disable or block the MDTM command where the server configuration allows it.
- Enforce strong, unique FTP credentials and least-privilege account permissions to limit who can reach the vulnerable command.
- Monitor vendor advisories for this product line and apply subsequent Serv-U security updates.
- Consider running the FTP service under a low-privilege account and isolating it from sensitive systems.
Detection
- Inspect FTP command logs for MDTM requests with unusually long or malformed time zone arguments.
- Alert on Serv-U service crashes or restarts that correlate with FTP sessions, which can indicate overflow attempts.
- Monitor for unexpected child processes or outbound connections originating from the Serv-U service process.
- Review authentication logs for FTP logins from unusual sources preceding anomalous MDTM activity.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2004-0330 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2004-0330), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.