← Vulnerability feed

Vulnerability record · CVE-2004-0330 · published 23 November 2004

CVE-2004-0330: Serv-U FTP MDTM time zone buffer overflow allows remote code execution

Solarwinds · Serv U File Server

Serv-U FTP versions before 5.0.0.4 contain a buffer overflow in the handling of the time zone argument to the MDTM command. A remote authenticated FTP user can send an overly long time zone value and overwrite memory, which matters because it can lead to arbitrary code execution on the FTP server.

10.0 CVSS 2.0 High EPSS 85% · top 0.3% CWE-119 · Memory buffer overflow
10.0CVSS 2.0 base score
85%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
8References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

Buffer overflow in Serv-U ftp before 5.0.0.4 allows remote authenticated users to execute arbitrary code via a long time zone argument to the MDTM command.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: medium.

high priorityThe flaw allows remote code execution with complete impact and has very high EPSS and public exploit references, though it requires valid FTP credentials and affects an old product version.

What it is

Serv-U FTP versions before 5.0.0.4 contain a buffer overflow in the handling of the time zone argument to the MDTM command. A remote authenticated FTP user can send an overly long time zone value and overwrite memory, which matters because it can lead to arbitrary code execution on the FTP server.

Impact

An attacker with valid FTP credentials gains the ability to execute arbitrary code in the context of the Serv-U service, potentially taking full control of the host. The CVSS 2.0 vector rates confidentiality, integrity and availability impact as complete.

Attack surface

The flaw is reached over the network through the FTP MDTM command, so no local access is required. Authentication is needed per the description, but no user interaction beyond issuing the crafted command is described.

Exploitation

The record is not listed in CISA KEV and no ransomware usage is documented, but EPSS is very high at 0.8547 (99.71st percentile) and a reference is tagged Exploit, indicating public exploit material exists.

What to do

  • Upgrade Serv-U FTP to version 5.0.0.4 or later, which is the fixed release named in the advisory.
  • If immediate upgrade is not possible, restrict FTP access to trusted networks and accounts, and disable or block the MDTM command where the server configuration allows it.
  • Enforce strong, unique FTP credentials and least-privilege account permissions to limit who can reach the vulnerable command.
  • Monitor vendor advisories for this product line and apply subsequent Serv-U security updates.
  • Consider running the FTP service under a low-privilege account and isolating it from sensitive systems.

Detection

  • Inspect FTP command logs for MDTM requests with unusually long or malformed time zone arguments.
  • Alert on Serv-U service crashes or restarts that correlate with FTP sessions, which can indicate overflow attempts.
  • Monitor for unexpected child processes or outbound connections originating from the Serv-U service process.
  • Review authentication logs for FTP logins from unusual sources preceding anomalous MDTM activity.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2004-0330 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2009-4006Serv-U FTP Server TEA Decoding Stack Buffer OverflowRhinoSoft Serv-U FTP server versions before 9.1.0.0 contain a stack-based buffer overflow in the TEA decoding algorithm. A remote attacker can trigge…EPSS 83%analysed10.0CVE-2004-2532Solarwinds serv-u file server vulnerabilityServ-U FTP server before 5.1.0.0 has a default account and password for local administration, which allows local users to execute arbitrary commands …EPSS 15%9.0CVE-2011-4800Solarwinds serv-u file server path traversal vulnerabilityDirectory traversal vulnerability in Serv-U FTP Server before 11.1.0.5 allows remote authenticated users to read and write arbitrary files, and list …EPSS 7.3%9.0CVE-2008-4501Solarwinds serv-u file server path traversal vulnerabilityDirectory traversal vulnerability in the FTP server in Serv-U 7.0.0.1 through 7.3, including 7.2.0.1, allows remote authenticated users to overwrite …EPSS 11%8.5CVE-2004-2111Serv-U FTP Server site chmod stack buffer overflowServ-U FTP Server before 4.2 has a stack-based buffer overflow in the site chmod command, triggered by a long filename. A remote attacker who can iss…EPSS 87%analysed7.8CVE-2009-1031Solarwinds serv-u file server path traversal vulnerabilityDirectory traversal vulnerability in the FTP server in Rhino Software Serv-U File Server 7.0.0.1 through 7.4.0.1 allows remote attackers to create ar…EPSS 11%7.5CVE-2001-1463Solarwinds serv-u file server vulnerabilityThe remote administration client for RhinoSoft Serv-U 3.0 sends the user password in plaintext even when S/KEY One-Time Password (OTP) authentication…EPSS 3.2%6.1CVE-2021-25179Solarwinds serv-u file server cross-site scripting vulnerabilitySolarWinds Serv-U before 15.2 is affected by Cross Site Scripting (XSS) via the HTTP Host header.EPSS 1.4%

Source: NIST National Vulnerability Database (record CVE-2004-0330), CISA KEV, FIRST EPSS (scores of 2026-09-24). This page is refreshed as NVD updates the record.